WebKit in Google Chrome before Blink M11 contains a bad cast to RenderBlock when anonymous blocks are renderblocks.
References
Link | Resource |
---|---|
http://trac.webkit.org/changeset/81648 | Mailing List Patch Vendor Advisory |
http://trac.webkit.org/changeset/81748 | Mailing List Patch Vendor Advisory |
https://bugs.chromium.org/p/chromium/issues/detail?id=76784 | Exploit Mailing List Vendor Advisory |
Configurations
History
No history.
Information
Published : 2019-11-05 23:15
Updated : 2024-02-04 20:39
NVD link : CVE-2011-1460
Mitre link : CVE-2011-1460
CVE.ORG link : CVE-2011-1460
JSON object : View
Products Affected
- blink
CWE
CWE-704
Incorrect Type Conversion or Cast