CVE-2010-3255
published 2010-09-07CVE-2010-3255: Google Chrome before 6.0.472.53 and webkitgtk before 1.2.6 do not properly handle counter nodes, which allows remote attackers to cause a denial of service…
PriorityP430critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.01%
79.0th percentile
Google Chrome before 6.0.472.53 and webkitgtk before 1.2.6 do not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 6.0.472.53 | 6.0.472.53 | |
| webkitgtk | webkitgtk | < 1.2.6 | 1.2.6 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkit: DoS via improper handling of counter nodes
vendor_redhat·2010-09-02·CVSS 9.3
CVE-2010-3255 [CRITICAL] webkit: DoS via improper handling of counter nodes
webkit: DoS via improper handling of counter nodes
Google Chrome before 6.0.472.53 and webkitgtk before 1.2.6 do not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
GHSA
GHSA-cfrv-wvvp-3q9q: Google Chrome before 6
ghsa_unreviewed·2022-05-13
CVE-2010-3255 [HIGH] CWE-119 GHSA-cfrv-wvvp-3q9q: Google Chrome before 6
Google Chrome before 6.0.472.53 and webkitgtk before 1.2.6 do not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4198 CVE-2010-4197 CVE-2010-4204 CVE-2010-4206 CVE-2010-3812 CVE-2010-3813 CVE-2010-4577 CVE-2010-3255 CVE-2010-3119 webkitgtk various flaws [fedora-13]
bugzilla·2011-01-04·CVSS 10.0
CVE-2010-4198 [CRITICAL] CVE-2010-4198 CVE-2010-4197 CVE-2010-4204 CVE-2010-4206 CVE-2010-3812 CVE-2010-3813 CVE-2010-4577 CVE-2010-3255 CVE-2010-3119 webkitgtk various flaws [fedora-13]
CVE-2010-4198 CVE-2010-4197 CVE-2010-4204 CVE-2010-4206 CVE-2010-3812 CVE-2010-3813 CVE-2010-4577 CVE-2010-3255 CVE-2010-3119 webkitgtk various flaws [fedora-13]
fedora-13 tracking bug for webkitgtk: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-4197
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=656118,656115
---
Adding parent bug CVE-2010-4206
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=656118,656115,656129
---
Adding parent bug CVE-2010-3812
New bodhi update url:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2010-3255 webkit: DoS via improper handling of counter nodes
bugzilla·2010-10-22·CVSS 9.3
CVE-2010-3255 [CRITICAL] CVE-2010-3255 webkit: DoS via improper handling of counter nodes
CVE-2010-3255 webkit: DoS via improper handling of counter nodes
Common Vulnerabilities and Exposures assigned an identifier to the following vulnerability:
Name: CVE-2010-3255
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3255
Assigned: 20100907
Reference: CONFIRM: http://code.google.com/p/chromium/issues/detail?id=51653
Reference: CONFIRM: http://googlechromereleases.blogspot.com/2010/09/stable-and-beta-channel-updates.html
Google Chrome before 6.0.472.53 does not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Other references:
https://bugs.webkit.org/show_bug.cgi?id=43812
http://trac.webkit.org/changeset/66052
Discussion:
Apple also assigned
http://code.google.com/p/chromium/issues/detail?id=51653http://googlechromereleases.blogspot.com/2010/09/stable-and-beta-channel-updates.htmlhttp://secunia.com/advisories/43086http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.redhat.com/support/errata/RHSA-2011-0177.htmlhttp://www.vupen.com/english/advisories/2011/0216http://www.vupen.com/english/advisories/2011/0552https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11736http://code.google.com/p/chromium/issues/detail?id=51653http://googlechromereleases.blogspot.com/2010/09/stable-and-beta-channel-updates.htmlhttp://secunia.com/advisories/43086http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.redhat.com/support/errata/RHSA-2011-0177.htmlhttp://www.vupen.com/english/advisories/2011/0216http://www.vupen.com/english/advisories/2011/0552https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11736
2010-09-07
Published