Google Security Advisories · January 2010 — Google Security Advisories
3 advisories 3 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2010-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2010-0315

GoogleActive exploitation (sightings)MEDIUM2010-01-14

WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK elemen...

CVEs:CVE-2010-0315

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-0280

GoogleEPSS <= 49%HIGH2010-01-15

Array index error in Jan Eric Kyprianidis lib3ds 1.x, as used in Google SketchUp 7.x before 7.1 M2, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted structures in a 3DS file, probab...

CVEs:CVE-2010-0280

Affected products

ProductStatusVendorPackageEcosystem
google_sketchup affected google
lib3ds affected jan_eric_krprianidis
Upstream advisory

CVE-2010-0316

GoogleEPSS <= 49%HIGH2010-01-15

Integer overflow in Google SketchUp before 7.1 M2 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via a crafted SKP file.

CVEs:CVE-2010-0316

Affected products

ProductStatusVendorPackageEcosystem
google_sketchup affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.