CVE-2008-6994 describes a stack-based buffer overflow vulnerability in Google Chrome version 0.2.149.27's SaveAs feature. This flaw allows user-assisted remote attackers to execute arbitrary code by crafting a web page with a long TITLE element, which triggers the overflow when the user saves the page and a long filename is generated. The vulnerability has a critical CVSS score of 9.3, indicating high severity with network accessibility, medium attack complexity, and complete impact on confidentiality, integrity, and availability. While not listed on the KEV catalog, public exploit code (EDB-6367) exists, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.2.149.27CPE matchmatch criteria | cpe:2.3:a:google:chrome:0.2.149.27:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.