CVE-2010-0664

N/A Unknown
Published: February 18, 2010 Modified: April 29, 2026
View on NVD

Description

Stack consumption vulnerability in the ChildProcessSecurityPolicy::CanRequestURL function in browser/child_process_security_policy.cc in Google Chrome before 4.0.249.78 allows remote attackers to cause a denial of service (memory consumption and application crash) via a URL that specifies multiple protocols, as demonstrated by a URL that begins with many repetitions of the view-source: substring.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://code.google.com/p/chromium/issues/detail?id=31517
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://exchange.kg/other/chrome3_0day-denial_of_service_crash.html
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://securitytracker.com/id?1023506
Source: af854a3a-2127-422b-91ae-364da2661108
http://sites.google.com/a/chromium.org/dev/Home/chromium-security/chromium-security-bugs
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://twitter.com/akirsanov/statuses/7370288490
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

14 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
1.3%
80th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

google