Vulnerabilities > CVE-2008-6996 - Unspecified vulnerability in Google Chrome 0.2.149.27

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
google
exploit available

Summary

Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to cause a denial of service (disk consumption) or exploit other vulnerabilities via a URL that references an executable file, possibly related to the "ask where to save each file before downloading" setting.

Vulnerable Configurations

Part Description Count
Application
Google
1

Exploit-Db

descriptionGoogle Chrome Browser 0.2.149.27 Automatic File Download Exploit. CVE-2008-6996. Remote exploit for windows platform
fileexploits/windows/remote/6355.txt
idEDB-ID:6355
last seen2016-02-01
modified2008-09-03
platformwindows
port
published2008-09-03
reporternerex
sourcehttps://www.exploit-db.com/download/6355/
titleGoogle Chrome Browser 0.2.149.27 Automatic File Download Exploit
typeremote