CVE-2008-6998

Google Chrome - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2.149.29 might allow user-assisted remote attackers to execute arbitrary code via a link target (href attribute) with a large number of path elements, which triggers the overflow when the status bar is updated after the user hovers over the link.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Shinnok · htmldoswindows
https://www.exploit-db.com/exploits/6372

Scores

EPSS 0.2176
EPSS Percentile 95.8%

Details

CWE
CWE-119
Status published
Products (1)
google/chrome 0.2.149.27
Published Aug 19, 2009
Tracked Since Feb 18, 2026