Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Google Chrome CSS越界读取漏洞
Vulnerability Description
Google Chrome是美国谷歌(Google)公司开发的一款Web浏览器。 在Google Chrome 8.0.552.224之前版本,Chrome OS 8.0.552.343之前版本,以及webkitgtk 1.2.6之前版本中使用的WebKit中的WebCore/css/CSSParser.cpp的CSSParser::parseFontFaceSrc函数没有正确解析层叠样式表(CSS)令牌序列。远程攻击者可借助未明向量导致拒绝服务(越界读取)。
CVSS Information
N/A
Vulnerability Type
N/A