CVE-2010-3114
published 2010-08-24CVE-2010-3114: The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has…
PriorityP430critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
1.79%
76.2th percentile
The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) InsertLineBreakCommand.cpp, or (3) InsertParagraphSeparatorCommand.cpp in WebCore/editing/.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| chrome | < 5.0.375.127 | 5.0.375.127 | |
| webkitgtk | webkitgtk | < 1.2.6 | 1.2.6 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6mv5-m43j-9667: The text-editing implementation in Google Chrome before 5
ghsa_unreviewed·2022-05-13
CVE-2010-3114 [HIGH] GHSA-6mv5-m43j-9667: The text-editing implementation in Google Chrome before 5
The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) InsertLineBreakCommand.cpp, or (3) InsertParagraphSeparatorCommand.cpp in WebCore/editing/.
Red Hat
webkit: bad cast with text editing
vendor_redhat·2010-08-19·CVSS 10.0
CVE-2010-3114 [CRITICAL] webkit: bad cast with text editing
webkit: bad cast with text editing
The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) InsertLineBreakCommand.cpp, or (3) InsertParagraphSeparatorCommand.cpp in WebCore/editing/.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3113 CVE-2010-1814 CVE-2010-1812 CVE-2010-1815 CVE-2010-3115 CVE-2010-1807 CVE-2010-3114 CVE-2010-3116 CVE-2010-3257 CVE-2010-3259 webkitgtk various flaws [fedora-all]
bugzilla·2010-10-05·CVSS 9.3
CVE-2010-3113 [CRITICAL] CVE-2010-3113 CVE-2010-1814 CVE-2010-1812 CVE-2010-1815 CVE-2010-3115 CVE-2010-1807 CVE-2010-3114 CVE-2010-3116 CVE-2010-3257 CVE-2010-3259 webkitgtk various flaws [fedora-all]
CVE-2010-3113 CVE-2010-1814 CVE-2010-1812 CVE-2010-1815 CVE-2010-3115 CVE-2010-1807 CVE-2010-3114 CVE-2010-3116 CVE-2010-3257 CVE-2010-3259 webkitgtk various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://adm
Bugzilla
CVE-2010-3114 webkit: bad cast with text editing
bugzilla·2010-08-27·CVSS 10.0
CVE-2010-3114 [CRITICAL] CVE-2010-3114 webkit: bad cast with text editing
CVE-2010-3114 webkit: bad cast with text editing
iCommon Vulnerabilities and Exposures assigned an identifier CVE-2010-3114 to
the following vulnerability:
Name: CVE-2010-3114
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3114
Assigned: 20100824
Reference: CONFIRM: http://code.google.com/p/chromium/issues/detail?id=49628
Reference: CONFIRM: http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.html
The text-editing implementation in Google Chrome before 5.0.375.127
does not properly perform casts, which has unspecified impact and
attack vectors.
This flaw also affects upstream WebKit:
https://bugs.webkit.org/show_bug.cgi?id=42655
http://trac.webkit.org/changeset/63773
Discussion:
This issue has been corrected in WebKitGTK 1.2.5.
---
Created webki
http://code.google.com/p/chromium/issues/detail?id=49628http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.htmlhttp://secunia.com/advisories/41856http://secunia.com/advisories/43086http://trac.webkit.org/changeset/63773http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.redhat.com/support/errata/RHSA-2011-0177.htmlhttp://www.securityfocus.com/bid/44201http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0216http://www.vupen.com/english/advisories/2011/0552https://bugzilla.redhat.com/show_bug.cgi?id=628035https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11577http://code.google.com/p/chromium/issues/detail?id=49628http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.htmlhttp://secunia.com/advisories/41856http://secunia.com/advisories/43086http://trac.webkit.org/changeset/63773http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.redhat.com/support/errata/RHSA-2011-0177.htmlhttp://www.securityfocus.com/bid/44201http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0216http://www.vupen.com/english/advisories/2011/0552https://bugzilla.redhat.com/show_bug.cgi?id=628035https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11577
2010-08-24
Published