CVE-2010-3254
published 2010-09-07CVE-2010-3254: The WebSockets implementation in Google Chrome before 6.0.472.53 does not properly handle integer values, which allows remote attackers to cause a denial of…
PriorityP429critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
1.82%
76.6th percentile
The WebSockets implementation in Google Chrome before 6.0.472.53 does not properly handle integer values, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 5.0.2 | — |
| apple | safari | <= 4.1.2 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9wc4-m3v7-7pr4: Integer underflow in WebKit in Apple Safari before 5
ghsa_unreviewed·2022-05-17·CVSS 10.0
CVE-2010-3805 [CRITICAL] GHSA-9wc4-m3v7-7pr4: Integer underflow in WebKit in Apple Safari before 5
Integer underflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving WebSockets. NOTE: this may overlap CVE-2010-3254.
GHSA
GHSA-7ccm-4xrg-v664: The WebSockets implementation in Google Chrome before 6
ghsa_unreviewed·2022-05-13
CVE-2010-3254 [HIGH] CWE-190 GHSA-7ccm-4xrg-v664: The WebSockets implementation in Google Chrome before 6
The WebSockets implementation in Google Chrome before 6.0.472.53 does not properly handle integer values, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
OSV
CVE-2010-3805: Integer underflow in WebKit in Apple Safari before 5
osv·2010-11-22·CVSS 10.0
CVE-2010-3805 [CRITICAL] CVE-2010-3805: Integer underflow in WebKit in Apple Safari before 5
Integer underflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving WebSockets. NOTE: this may overlap CVE-2010-3254.
OSV
CVE-2010-3254: The WebSockets implementation in Google Chrome before 6
osv·2010-09-07·CVSS 10.0
CVE-2010-3254 [CRITICAL] CVE-2010-3254: The WebSockets implementation in Google Chrome before 6
The WebSockets implementation in Google Chrome before 6.0.472.53 does not properly handle integer values, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2011-08-23
CVE-2010-1824 WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: Multiple security vulnerabilities were fixed in WebKit.
A large number of security issues were discovered in the WebKit browser and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of
service attacks, and arbitrary code execution.
Instructions: After a standard system update you need to restart any applications that
use WebKit, such as Epiphany and Midori, to make all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=51630http://code.google.com/p/chromium/issues/detail?id=51739http://googlechromereleases.blogspot.com/2010/09/stable-and-beta-channel-updates.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12119http://code.google.com/p/chromium/issues/detail?id=51630http://code.google.com/p/chromium/issues/detail?id=51739http://googlechromereleases.blogspot.com/2010/09/stable-and-beta-channel-updates.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12119
2010-09-07
Published