Back

HIGH

webkit: CSS Font Face Parsing Type Confusion Vulnerability

Published Dec 22, 2010

Description

The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."

Affected products

Remediation

No remediation recorded yet.

Metrics

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 22, 2010
Updated Jan 21, 2025
Reserved Dec 21, 2010
CISA Vulnrichment
Updated Feb 5, 2024
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Dec 13, 2010