Google Security Advisories · November 2010 — Google Security Advisories
10 advisories 10 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2010-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2010-4008

GooglePoC exploitHIGH2010-11-08

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to caus...

CVEs:CVE-2010-4008

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_server_eus affected redhat
enterprise_linux_workstation affected redhat
iphone_os affected apple
itunes affected apple
libxml2 affected xmlsoft
mac_os_x affected apple
openoffice affected apache
opensuse affected opensuse
safari affected apple
suse_linux_enterprise_server affected suse
ubuntu_linux affected canonical
Upstream advisory

CVE-2010-4203

GoogleEPSS <= 49%HIGH2010-11-05

WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.

CVEs:CVE-2010-4203

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
libvpx affected webmproject
Upstream advisory

CVE-2010-4206

GoogleEPSS <= 49%CRITICAL2010-11-05

Array index error in the FEBlend::apply function in WebCore/platform/graphics/filters/FEBlend.cpp in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service an...

CVEs:CVE-2010-4206

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
webkitgtk affected webkitgtk
Upstream advisory

CVE-2010-4197

GoogleEPSS <= 49%CRITICAL2010-11-05

Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text ed...

CVEs:CVE-2010-4197

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
webkitgtk affected webkitgtk
Upstream advisory

CVE-2010-4204

GoogleEPSS <= 49%CRITICAL2010-11-05

WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, accesses a frame object after this object has been destroyed, which allows remote attackers to cause a denial of service or possibly have unspecified other ...

CVEs:CVE-2010-4204

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
webkitgtk affected webkitgtk
Upstream advisory

CVE-2010-4198

GoogleEPSS <= 49%CRITICAL2010-11-05

WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does not properly handle large text areas, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other...

CVEs:CVE-2010-4198

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
fedora affected fedoraproject
webkitgtk affected webkitgtk
Upstream advisory

CVE-2010-4205

GoogleEPSS <= 49%CRITICAL2010-11-05

Google Chrome before 7.0.517.44 does not properly handle the data types of event objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVEs:CVE-2010-4205

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4202

GoogleEPSS <= 49%CRITICAL2010-11-05

Multiple integer overflows in Google Chrome before 7.0.517.44 on Linux allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted font.

CVEs:CVE-2010-4202

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4201

GoogleEPSS <= 49%CRITICAL2010-11-05

Use-after-free vulnerability in Google Chrome before 7.0.517.44 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text control selections.

CVEs:CVE-2010-4201

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4199

GoogleEPSS <= 49%HIGH2010-11-05

Google Chrome before 7.0.517.44 does not properly perform a cast of an unspecified variable during processing of an SVG use element, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SVG ...

CVEs:CVE-2010-4199

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.