Total vulnerabilities in the database
The EditingStyle::mergeStyle function in WebKit/Source/core/editing/EditingStyle.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, mishandles custom properties, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site that leverages "type confusion" in the StylePropertySerializer class.
Software | From | Fixed in |
---|---|---|
google / chrome | - | 52.0.2743.116.x |
opensuse / leap | 42.1 | 42.1.x |