Unrated severityNVD Advisory· Published Aug 19, 2009· Updated Apr 23, 2026
CVE-2008-6998
CVE-2008-6998
Description
Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2.149.29 might allow user-assisted remote attackers to execute arbitrary code via a link target (href attribute) with a large number of path elements, which triggers the overflow when the status bar is updated after the user hovers over the link.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- src.chromium.org/viewvc/chrome/branches/chrome_official_branch/src/chrome/common/gfx/url_elider.ccnvdPatch
- shinnok.evonet.ro/vulns_html/chrome.htmlnvdExploit
- www.securityfocus.com/bid/31034nvdExploit
- www.securityfocus.com/bid/31071nvdExploit
- googlechromereleases.blogspot.com/2008/09/beta-release-0214929.htmlnvdVendor Advisory
- osvdb.org/48264nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/44934nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/45032nvd
- www.exploit-db.com/exploits/6372nvd
News mentions
0No linked articles in our index yet.