VYPR
High severity7.5NVD Advisory· Published Dec 22, 2010· Updated Apr 29, 2026

CVE-2010-4577

CVE-2010-4577

Description

The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."

Affected products

6
  • cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
    Range: <8.0.552.224
  • cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*
    Range: <1.2.6
  • cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:*
  • cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:*
    Range: <8.0.552.343

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

15

News mentions

0

No linked articles in our index yet.