Google Chrome before 5.0.375.127, and webkitgtk before 1.2.5, does not properly handle SVG documents, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors related to state changes when using DeleteButtonController.
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=628032
No PoCs found on GitHub currently.