CVE-2010-1823 — Use After Free in Google Chrome
Severity
9.3CRITICALNVD
EPSS
1.9%
top 16.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateMay 13
Description
Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger use of document APIs such as document.close during parsing, as demonstrated by a Cascading Style Sheets (CSS) file referencing an invalid SVG font, aka rdar problem 8442098.
CVSS vector
AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0
Affected Packages3 packages
Patches
🔴Vulnerability Details
1GHSA▶
GHSA-29qv-h4j6-wvj9: Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6↗2022-05-13