CVE-2010-4198
published 2010-11-06CVE-2010-4198: WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does not properly handle large text areas, which allows remote…
PriorityP428high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.50%
71.4th percentile
WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does not properly handle large text areas, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted HTML document.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| chrome | < 7.0.517.44 | 7.0.517.44 | |
| webkitgtk | webkitgtk | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mr33-529g-h782: WebKit, as used in Google Chrome before 7
ghsa_unreviewed·2022-05-13
CVE-2010-4198 [HIGH] CWE-20 GHSA-mr33-529g-h782: WebKit, as used in Google Chrome before 7
WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does not properly handle large text areas, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted HTML document.
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2011-08-23
CVE-2010-1824 WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: Multiple security vulnerabilities were fixed in WebKit.
A large number of security issues were discovered in the WebKit browser and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of
service attacks, and arbitrary code execution.
Instructions: After a standard system update you need to restart any applications that
use WebKit, such as Epiphany and Midori, to make all the necessary changes.
Red Hat
WebKit: Memory corruption due to improper handling of large text area
vendor_redhat·2010-11-04·CVSS 8.8
CVE-2010-4198 [HIGH] WebKit: Memory corruption due to improper handling of large text area
WebKit: Memory corruption due to improper handling of large text area
WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does not properly handle large text areas, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted HTML document.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4198 CVE-2010-4197 CVE-2010-4204 CVE-2010-4206 CVE-2010-3812 CVE-2010-3813 CVE-2010-4577 CVE-2010-3255 CVE-2010-3119 webkitgtk various flaws [fedora-13]
bugzilla·2011-01-04·CVSS 10.0
CVE-2010-4198 [CRITICAL] CVE-2010-4198 CVE-2010-4197 CVE-2010-4204 CVE-2010-4206 CVE-2010-3812 CVE-2010-3813 CVE-2010-4577 CVE-2010-3255 CVE-2010-3119 webkitgtk various flaws [fedora-13]
CVE-2010-4198 CVE-2010-4197 CVE-2010-4204 CVE-2010-4206 CVE-2010-3812 CVE-2010-3813 CVE-2010-4577 CVE-2010-3255 CVE-2010-3119 webkitgtk various flaws [fedora-13]
fedora-13 tracking bug for webkitgtk: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-4197
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=656118,656115
---
Adding parent bug CVE-2010-4206
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=656118,656115,656129
---
Adding parent bug CVE-2010-3812
New bodhi update url:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2010-4198 WebKit: Memory corruption due to improper handling of large text area
bugzilla·2010-11-23·CVSS 8.8
CVE-2010-4198 [HIGH] CVE-2010-4198 WebKit: Memory corruption due to improper handling of large text area
CVE-2010-4198 WebKit: Memory corruption due to improper handling of large text area
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4198 to
the following vulnerability:
Name: CVE-2010-4198
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4198 [Open URL]
Assigned: 20101105
Reference: CONFIRM:http://code.google.com/p/chromium/issues/detail?id=55257
Reference: CONFIRM:http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.html
Upstream Bugzilla: https://bugs.webkit.org/show_bug.cgi?id=45611
Trac: http://trac.webkit.org/changeset/69801
Google Chrome before 7.0.517.44 does not properly handle large text
areas, which allows remote attackers to cause a denial of service
(memory corruption) or possibly have unspecified other imp
http://code.google.com/p/chromium/issues/detail?id=55257http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/052906.htmlhttp://secunia.com/advisories/42109http://secunia.com/advisories/43086http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.redhat.com/support/errata/RHSA-2011-0177.htmlhttp://www.securityfocus.com/bid/45719http://www.vupen.com/english/advisories/2011/0216http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=45611https://bugzilla.redhat.com/show_bug.cgi?id=656118https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12157http://code.google.com/p/chromium/issues/detail?id=55257http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/052906.htmlhttp://secunia.com/advisories/42109http://secunia.com/advisories/43086http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.redhat.com/support/errata/RHSA-2011-0177.htmlhttp://www.securityfocus.com/bid/45719http://www.vupen.com/english/advisories/2011/0216http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=45611https://bugzilla.redhat.com/show_bug.cgi?id=656118https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12157
2010-11-06
Published