Lucene search

K
cveMitreCVE-2010-3254
HistorySep 07, 2010 - 6:00 p.m.

CVE-2010-3254

2010-09-0718:00:02
CWE-190
mitre
web.nvd.nist.gov
33
cve-2010-3254
websockets
google chrome
integer values
denial of service
security vulnerability

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

9.4

Confidence

High

EPSS

0.005

Percentile

77.3%

The WebSockets implementation in Google Chrome before 6.0.472.53 does not properly handle integer values, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

Affected configurations

Nvd
Node
googlechromeRange<6.0.472.53
VendorProductVersionCPE
googlechrome*cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

9.4

Confidence

High

EPSS

0.005

Percentile

77.3%