VDB
CVE-2008-6995
CVE-2008-6995
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash) via a URI with an invalid handler followed by a "%" (percent) character, which triggers a buffer over-read, as demonstrated using an "about:%" URI.
EPSS 8.07% · 92.3th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
8.07%
92.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| chrome | 0.2.149.27 |
Exploit Intelligence
- http://code.google.com/p/chromium/issues/detail?id=122 (circl)
- google-chrome-handlers-dos(44899) (circl)
- http://archives.neohapsis.com/archives/bugtraq/2008-09/0028.html (vulncheck-nvd)
- http://evilfingers.com/advisory/google_chrome_poc.php (vulncheck-nvd)
- http://osvdb.org/47908 (vulncheck-nvd)
- http://src.chromium.org/viewvc/chrome/branches/chrome_official_branch/src/net/base/escape.cc?r1=1757&r2=1760&pathrev=1760 (vulncheck-nvd)
- http://www.securityfocus.com/bid/30983 (vulncheck-nvd)
- https://www.evilfingers.com/advisory/Google_Chrome_Browser_0.2.149.27_in_chrome_dll.php (vulncheck-nvd)
- 6353 (cve.org)
Timeline
- Aug 18, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 47908 vdb
- https://www.evilfingers.com/advisory/Google_Chrome_Browser_0.2.149.27_in_chrome_dll.php url
- 20080902 Google Chrome Browser (ver.0.2.149.27) Vulnerability mailing-list
- http://src.chromium.org/viewvc/chrome/branches/chrome_official_branch/src/net/base/escape.cc?r1=1757&r2=1760&pathrev=1760 url
- http://evilfingers.com/advisory/google_chrome_poc.php url
- http://code.google.com/p/chromium/issues/detail?id=122 url
- google-chrome-handlers-dos(44899) vdb
- 30983 vdb
- 6353 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2008-6995 advisory