Use-after-free vulnerability in the FrameView::calculateScrollbarModesForLayout function in page/FrameView.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that calls the removeChild method during interaction with a FRAME element. <a href"http://cwe.mitre.org/data/definitions/416.html">CWE-416: Use After Free</a>
Publication date: Fri, 26 Dec 2014 08:59:00 +0000