Vulnerabilities > CVE-2010-2299 - Type Confusion vulnerability in Google Chrome
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 does not properly handle CBF_SMBITMAP objects in a ViewHostMsg_ClipboardWriteObjectsAsync message, which might allow remote attackers to execute arbitrary code via vectors involving crafted data from the renderer process, related to a "Type Confusion" issue.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Nessus
NASL family | Windows |
NASL id | GOOGLE_CHROME_5_0_375_70.NASL |
description | The version of Google Chrome installed on the remote host is earlier than 5.0.375.70. As such, it is reportedly affected by multiple vulnerabilities : - A cross-origin keystroke redirection vulnerability. (Issue #15766) - A cross-origin bypass in DOM methods. (Issue #39985) - A memory error exists in table layout. (Issue #42723) - It is possible to escape the sandbox in Linux. (Issue #43304) - A stale pointer exists in bitmap. (Issue #43307) - A memory corruption vulnerability exists in DOM node normalization. (Issue #43315) - A memory corruption vulnerability exists in text transforms. (Issue #43487) - A cross-site scripting vulnerability exists in the innerHTML property of textarea. (Issue #43902) - A memory corruption vulnerability exists in font handling. (Issue #44740) - Geolocation events fire after document deletion. (Issue #44868) - A memory corruption vulnerability exists in the rendering of list markers. (Issue #44955) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 46850 |
published | 2010-06-09 |
reporter | This script is Copyright (C) 2010-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/46850 |
title | Google Chrome < 5.0.375.70 Multiple Vulnerabilities |
code |
|
Oval
accepted | 2013-08-12T04:00:59.602-04:00 | ||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||
description | The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 does not properly handle CBF_SMBITMAP objects in a ViewHostMsg_ClipboardWriteObjectsAsync message, which might allow remote attackers to execute arbitrary code via vectors involving crafted data from the renderer process, related to a "Type Confusion" issue. | ||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||
id | oval:org.mitre.oval:def:12099 | ||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||
submitted | 2010-08-26T11:57:22 | ||||||||||||||||||||||||
title | Vulnerability in Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 | ||||||||||||||||||||||||
version | 50 |
References
- http://code.google.com/p/chromium/issues/detail?id=43307
- http://code.google.com/p/chromium/issues/detail?id=43307
- http://googlechromereleases.blogspot.com/2010/06/stable-channel-update.html
- http://googlechromereleases.blogspot.com/2010/06/stable-channel-update.html
- http://secunia.com/advisories/40072
- http://secunia.com/advisories/40072
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12099
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12099