Google Security Advisories · March 2010 — Google Security Advisories
2 advisories 2 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2010-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2010-1029

GoogleActive exploitation (sightings)CRITICAL2010-03-19

Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to cause a denial of service (appl...

CVEs:CVE-2010-1029

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
safari affected apple
Upstream advisory

CVE-2010-0957

Open SourceEPSS <= 49%CRITICAL2010-03-09

Directory traversal vulnerability in content.php in Saskia's Shopsystem beta1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter.

CVEs:CVE-2010-0957

Affected products

ProductStatusVendorPackageEcosystem
saskias_shopsystem affected saskia_bruckner
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.