Advisories
GoogleWeaponized exploitCRITICAL2010-06-25
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
CVEs:CVE-2010-1205
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| firefox |
affected |
mozilla |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| itunes |
affected |
apple |
— |
— |
| libpng |
affected |
libpng |
— |
— |
| linux_enterprise_server |
affected |
suse |
— |
— |
| mac_os_x |
affected |
apple |
— |
— |
| mac_os_x_server |
affected |
apple |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| player |
affected |
vmware |
— |
— |
| safari |
affected |
apple |
— |
— |
| seamonkey |
affected |
mozilla |
— |
— |
| thunderbird |
affected |
mozilla |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
| workstation |
affected |
vmware |
— |
— |
GoogleEPSS <= 49%HIGH2010-06-11
Use-after-free vulnerability in the Element::normalizeAttributes function in dom/Element.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via ...
CVEs:CVE-2010-2300
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2010-06-07
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, whic...
CVEs:CVE-2010-1770
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| safari |
affected |
apple |
— |
— |
| suse_linux_enterprise_desktop |
affected |
suse |
— |
— |
| suse_linux_enterprise_server |
affected |
suse |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
| webkit |
affected |
apple |
— |
— |
GoogleEPSS <= 49%HIGH2010-06-11
Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving remote fonts in conjunction with shad...
CVEs:CVE-2010-2302
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| suse_linux_enterprise_desktop |
affected |
suse |
— |
— |
| suse_linux_enterprise_server |
affected |
suse |
— |
— |
GoogleEPSS <= 49%HIGH2010-06-11
rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an HTML document that has a large colspan attribute w...
CVEs:CVE-2010-2297
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| suse_linux_enterprise_desktop |
affected |
suse |
— |
— |
| suse_linux_enterprise_server |
affected |
suse |
— |
— |
GoogleEPSS <= 49%HIGH2010-06-11
The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 does not properly handle CBF_SMBITMAP objects in a ViewHostMsg_ClipboardWriteObjectsAsync message, which might allow remote attackers to execute arb...
CVEs:CVE-2010-2299
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2010-06-11
browser/renderer_host/database_dispatcher_host.cc in Google Chrome before 5.0.375.70 on Linux does not properly handle ViewHostMsg_DatabaseOpenFile messages in chroot-based sandboxing, which allows remote attackers to bypass intended sandbox restrictio...
CVEs:CVE-2010-2298
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2010-06-11
The implementation of unspecified DOM methods in Google Chrome before 5.0.375.70 allows remote attackers to bypass the Same Origin Policy via unknown vectors.
CVEs:CVE-2010-2296
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2010-06-11
page/EventHandler.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 does not properly handle a change of the focused frame during the dispatching of keydown, which allows user-assisted remote attackers to redirect keystrokes via a crafted HTM...
CVEs:CVE-2010-2295
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%CRITICAL2010-06-11
Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA eleme...
CVEs:CVE-2010-2301
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| opensuse |
affected |
opensuse |
— |
— |
| suse_linux_enterprise_desktop |
affected |
suse |
— |
— |
| suse_linux_enterprise_server |
affected |
suse |
— |
— |
GoogleEPSS <= 49%CRITICAL2010-06-01
Google Chrome 1.0.154.48 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.
CVEs:CVE-2010-2120
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |