Google Security Advisories · May 2010 — Google Security Advisories
9 advisories 9 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2010-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2010-2108

GoogleEPSS <= 49%HIGH2010-05-28

Unspecified vulnerability in Google Chrome before 5.0.375.55 allows remote attackers to bypass the whitelist-mode plugin blocker via unknown vectors.

CVEs:CVE-2010-2108

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2109

GoogleEPSS <= 49%HIGH2010-05-28

Unspecified vulnerability in Google Chrome before 5.0.375.55 allows user-assisted remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via vectors related to the "drag + drop" functionality.

CVEs:CVE-2010-2109

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-1992

GoogleEPSS <= 49%HIGH2010-05-20

Google Chrome 1.0.154.48 executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with man...

CVEs:CVE-2010-1992

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2105

GoogleEPSS <= 49%HIGH2010-05-28

Google Chrome before 5.0.375.55 does not properly follow the Safe Browsing specification's requirements for canonicalization of URLs, which has unspecified impact and remote attack vectors.

CVEs:CVE-2010-2105

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2107

GoogleEPSS <= 49%HIGH2010-05-28

Unspecified vulnerability in Google Chrome before 5.0.375.55 allows attackers to cause a denial of service (memory error) or possibly have unspecified other impact via vectors related to the Safe Browsing functionality.

CVEs:CVE-2010-2107

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2106

GoogleEPSS <= 49%MEDIUM2010-05-28

Unspecified vulnerability in Google Chrome before 5.0.375.55 might allow remote attackers to spoof the URL bar via vectors involving unload event handlers.

CVEs:CVE-2010-2106

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2110

GoogleEPSS <= 49%HIGH2010-05-28

Google Chrome before 5.0.375.55 does not properly execute JavaScript code in the extension context, which has unspecified impact and remote attack vectors.

CVEs:CVE-2010-2110

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-1731

GoogleEPSS <= 49%HIGH2010-05-05

Google Chrome on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop.

CVEs:CVE-2010-1731

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-1851

GoogleEPSS <= 49%HIGH2010-05-07

Google Chrome, when the Invisible Hand extension is enabled, uses cookies during background HTTP requests in a possibly unexpected manner, which might allow remote web servers to identify specific persons and their product searches via HTTP request log...

CVEs:CVE-2010-1851

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.