Google Security Advisories · October 2010 — Google Security Advisories
13 advisories 13 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2010-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2010-1822

GoogleEPSS <= 49%CRITICAL2010-10-04

WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3 and Google Chrome before 6.0.472.62, does not properly perform a cast of an unspecified variable, which allows remote attackers to execute arbitrary code or cause a denial of service (...

CVEs:CVE-2010-1822

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
safari affected apple
Upstream advisory

CVE-2010-3729

GoogleEPSS <= 49%CRITICAL2010-10-05

The SPDY protocol implementation in Google Chrome before 6.0.472.62 does not properly manage buffers, which might allow remote attackers to execute arbitrary code via unspecified vectors.

CVEs:CVE-2010-3729

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4034

GoogleEPSS <= 49%HIGH2010-10-21

Google Chrome before 7.0.517.41 does not properly handle forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.

CVEs:CVE-2010-4034

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4035

GoogleEPSS <= 49%HIGH2010-10-21

Google Chrome before 7.0.517.41 does not properly perform autofill operations for forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.

CVEs:CVE-2010-4035

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4042

GoogleEPSS <= 49%CRITICAL2010-10-21

Google Chrome before 7.0.517.41 does not properly handle element maps, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "stale elements."

CVEs:CVE-2010-4042

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
opensuse affected opensuse
Upstream advisory

CVE-2010-4041

GoogleEPSS <= 49%CRITICAL2010-10-21

The sandbox implementation in Google Chrome before 7.0.517.41 on Linux does not properly constrain worker processes, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.

CVEs:CVE-2010-4041

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4038

GoogleEPSS <= 49%HIGH2010-10-21

The Web Sockets implementation in Google Chrome before 7.0.517.41 does not properly handle a shutdown action, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

CVEs:CVE-2010-4038

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4040

GoogleEPSS <= 49%CRITICAL2010-10-21

Google Chrome before 7.0.517.41 does not properly handle animated GIF images, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted image.

CVEs:CVE-2010-4040

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
opensuse affected opensuse
Upstream advisory

CVE-2010-4039

GoogleEPSS <= 49%CRITICAL2010-10-21

Google Chrome before 7.0.517.41 on Linux does not properly set the PATH environment variable, which has unspecified impact and attack vectors.

CVEs:CVE-2010-4039

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4037

GoogleEPSS <= 49%MEDIUM2010-10-21

Unspecified vulnerability in Google Chrome before 7.0.517.41 allows remote attackers to bypass the pop-up blocker via unknown vectors.

CVEs:CVE-2010-4037

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4033

GoogleEPSS <= 49%MEDIUM2010-10-21

Google Chrome before 7.0.517.41 does not properly implement the autofill and autocomplete functionality, which allows remote attackers to conduct "profile spamming" attacks via unspecified vectors.

CVEs:CVE-2010-4033

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4036

GoogleEPSS <= 49%MEDIUM2010-10-21

Google Chrome before 7.0.517.41 does not properly handle the unloading of a page, which allows remote attackers to spoof URLs via unspecified vectors.

CVEs:CVE-2010-4036

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-3730

GoogleEPSS <= 49%HIGH2010-10-05

Google Chrome before 6.0.472.62 does not properly use information about the origin of a document to manage properties, which allows remote attackers to have an unspecified impact via a crafted web site, related to a "property pollution" issue.

CVEs:CVE-2010-3730

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.