CVE-2008-6996
Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to cause a denial of service (disk consumption) or exploit other vulnerabilities via a URL that references…
Does this matter?
Lower severity and a low EPSS score (6.42%). Track it; it rarely justifies an emergency change on its own.
Description
Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to cause a denial of service (disk consumption) or exploit other vulnerabilities via a URL that references an executable file, possibly related to the "ask where to save each file before downloading" setting.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 6.42% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- google/chrome
- Source
- cve@mitre.org
References
- http://codereview.chromium.org/472/diff/1/2Exploit
- http://src.chromium.org/viewvc/chrome?view=rev&revision=1793
- http://www.osvdb.org/48261
- http://www.securityfocus.com/archive/1/495942/100/0/threaded
- http://www.securityfocus.com/archive/1/495951/100/100/threaded
- http://www.securityfocus.com/archive/1/495954/100/100/threaded
- http://www.securityfocus.com/archive/1/495959/100/100/threaded
- http://www.securityfocus.com/archive/1/495987/100/0/threaded
- http://www.securityfocus.com/archive/1/496048/100/100/threaded
- http://www.securityfocus.com/archive/1/496049
- http://www.securityfocus.com/bid/31000
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44904
- https://www.exploit-db.com/exploits/6355
- http://codereview.chromium.org/472/diff/1/2Exploit
- http://src.chromium.org/viewvc/chrome?view=rev&revision=1793
- http://www.osvdb.org/48261
- http://www.securityfocus.com/archive/1/495942/100/0/threaded
- http://www.securityfocus.com/archive/1/495951/100/100/threaded
- http://www.securityfocus.com/archive/1/495954/100/100/threaded
- http://www.securityfocus.com/archive/1/495959/100/100/threaded
- http://www.securityfocus.com/archive/1/495987/100/0/threaded
- http://www.securityfocus.com/archive/1/496048/100/100/threaded
- http://www.securityfocus.com/archive/1/496049
- http://www.securityfocus.com/bid/31000
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44904
- https://www.exploit-db.com/exploits/6355
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.