CVE-2008-6995 describes an integer underflow vulnerability in Google Chrome version 0.2.149.27, specifically within the net/base/escape.cc component of chrome.dll. This flaw allows remote attackers to trigger a denial of service (browser crash) by crafting a malicious URI containing an invalid handler followed by a percent character, leading to a buffer over-read. The vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity, requiring no authentication, and resulting in partial availability impact. Its FAUCET Risk Score is 82/100, highlighting its potential. While not actively exploited in the wild (no KEV entry), exploit code is publicly available via ExploitDB (EDB-6353). There is minimal community discussion or media coverage surrounding this decade-old vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.2.149.27CPE matchmatch criteria | cpe:2.3:a:google:chrome:0.2.149.27:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.