Summary
The host is running Google Chrome and is prone to multiple vulnerabilities.
Impact
Successful exploitation could allow the attackers to cause denial of service.
Impact Level: Application
Solution
Upgrade to the Google Chrome 5.0.375.55 or later,
For updates refer to http://www.google.com/chromeVer
Insight
Multiple flaws are due to:
- An error in canonicalization of URLs, which does not properly follow the safe browsing 'specification&qts' requirements for canonicalization of 'URLs'.
- A memory error when processing vectors related to the Safe Browsing functionality.
- Unspecified erorrs when processing vectors involving 'unload' event handlers, which allow remote attackers to spoof the URL bar.
- Unspecified errors when processing unknown vectors, which allows remote attackers to bypass the 'whitelist-mode' plugin blocker.
- Unspecified errors when handling the vectors related to the 'drag + drop' functionality allows remote attackers to cause a denial of service.
- It does not properly execute 'JavaScript' code in the extension context, which has unspecified impact and remote attack vectors.
Affected
Google Chrome version prior to 5.0.375.55
References
Severity
Classification
-
CVE CVE-2010-2105, CVE-2010-2106, CVE-2010-2107, CVE-2010-2108, CVE-2010-2109, CVE-2010-2110 -
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities