CVE-2010-2297Code Injection in Google Chrome

CWE-94Code Injection4 documents4 sources
Severity
9.3CRITICALNVD
EPSS
7.1%
top 8.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15
Latest updateMay 13

Description

rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an HTML document that has a large colspan attribute within a table.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-m7xr-924m-mc34: rendering/FixedTableLayout2022-05-13
CVEList
CVE-2010-2297: rendering/FixedTableLayout2010-06-15

💥Exploits & PoCs

1
Exploit-DB
Sybase EAServer 5.2 - Remote Stack Buffer Overflow (Metasploit)2010-06-22
CVE-2010-2297 — Code Injection in Google Chrome | cvebase