Google Security Advisories · July 2010 — Google Security Advisories
15 advisories 15 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2010-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2010-2901

GoogleEPSS <= 49%HIGH2010-07-28

The rendering implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2010-2901

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2010-2647

GoogleEPSS <= 49%HIGH2010-07-06

Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an invalid SVG document.

CVEs:CVE-2010-2647

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
ubuntu_linux affected canonical
Upstream advisory

CVE-2010-2648

GoogleEPSS <= 49%HIGH2010-07-06

The implementation of the Unicode Bidirectional Algorithm (aka Bidi algorithm or UBA) in Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vect...

CVEs:CVE-2010-2648

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
ubuntu_linux affected canonical
Upstream advisory

CVE-2010-2902

GoogleEPSS <= 49%HIGH2010-07-28

The SVG implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2010-2902

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2897

GoogleEPSS <= 49%HIGH2010-07-28

Google Chrome before 5.0.375.125 does not properly mitigate an unspecified flaw in the Windows kernel, which has unknown impact and attack vectors.

CVEs:CVE-2010-2897

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2651

GoogleEPSS <= 49%HIGH2010-07-06

The Cascading Style Sheets (CSS) implementation in Google Chrome before 5.0.375.99 does not properly perform style rendering, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via u...

CVEs:CVE-2010-2651

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2898

GoogleEPSS <= 49%HIGH2010-07-28

Google Chrome before 5.0.375.125 does not properly mitigate an unspecified flaw in the GNU C Library, which has unknown impact and attack vectors.

CVEs:CVE-2010-2898

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2900

GoogleEPSS <= 49%HIGH2010-07-28

Google Chrome before 5.0.375.125 does not properly handle a large canvas, which has unspecified impact and remote attack vectors.

CVEs:CVE-2010-2900

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2899

GoogleEPSS <= 49%HIGH2010-07-28

Unspecified vulnerability in the layout implementation in Google Chrome before 5.0.375.125 allows remote attackers to obtain sensitive information from process memory via unknown vectors.

CVEs:CVE-2010-2899

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2649

GoogleEPSS <= 49%HIGH2010-07-06

Unspecified vulnerability in Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (application crash) via an invalid image.

CVEs:CVE-2010-2649

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2645

GoogleEPSS <= 49%HIGH2010-07-06

Unspecified vulnerability in Google Chrome before 5.0.375.99, when WebGL is used, allows remote attackers to cause a denial of service (out-of-bounds read) via unknown vectors.

CVEs:CVE-2010-2645

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2646

GoogleEPSS <= 49%HIGH2010-07-06

Google Chrome before 5.0.375.99 does not properly isolate sandboxed IFRAME elements, which has unspecified impact and remote attack vectors.

CVEs:CVE-2010-2646

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2903

GoogleEPSS <= 49%HIGH2010-07-28

Google Chrome before 5.0.375.125 performs unexpected truncation and improper eliding of hostnames, which has unspecified impact and remote attack vectors.

CVEs:CVE-2010-2903

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2650

GoogleEPSS <= 49%HIGH2010-07-06

Unspecified vulnerability in Google Chrome before 5.0.375.99 has unknown impact and attack vectors, related to an "annoyance with print dialogs."

CVEs:CVE-2010-2650

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-2652

GoogleEPSS <= 49%HIGH2010-07-06

Google Chrome before 5.0.375.99 does not properly implement modal dialogs, which allows attackers to cause a denial of service (application crash) via unspecified vectors.

CVEs:CVE-2010-2652

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.