CVE-2010-0659: The image decoder in WebKit before r52833, as used in Google Chrome be ...

Severity: Critical

CVSS Score: 9.3

The image decoder in WebKit before r52833, as used in Google Chrome before 4.0.249.78, does not properly handle a failure of memory allocation, which allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed GIF file that specifies a large size.