Google Security Advisories · December 2010 — Google Security Advisories
18 advisories 18 CVEs

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2010-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2010-4577

GoogleWeaponized exploitHIGH2010-12-22

The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) ...

CVEs:CVE-2010-4577

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
debian_linux affected debian
fedora affected fedoraproject
webkitgtk affected webkitgtk
Upstream advisory

CVE-2010-4494

GooglePoC exploitCRITICAL2010-12-02

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath h...

CVEs:CVE-2010-4494

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_eus affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
insight_control_server_deployment affected hp
iphone_os affected apple
itunes affected apple
libxml2 affected xmlsoft
mac_os_x affected apple
openoffice affected apache
opensuse affected opensuse
rapid_deployment_pack affected hp
safari affected apple
suse_linux_enterprise_server affected suse
Upstream advisory

CVE-2010-4574

GoogleEPSS <= 49%HIGH2010-12-22

The Pickle::Pickle function in base/pickle.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 on 64-bit Linux platforms does not properly perform pointer arithmetic, which allows remote attackers to bypass message deserialization v...

CVEs:CVE-2010-4574

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2010-4576

GoogleEPSS <= 49%HIGH2010-12-22

browser/worker_host/message_port_dispatcher.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle certain postMessage calls, which allows remote attackers to cause a denial of service (NULL pointer dereference...

CVEs:CVE-2010-4576

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2010-4578

GoogleEPSS <= 49%HIGH2010-12-22

Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale poin...

CVEs:CVE-2010-4578

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
debian_linux affected debian
Upstream advisory

CVE-2010-4492

GoogleEPSS <= 49%CRITICAL2010-12-07

Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animations.

CVEs:CVE-2010-4492

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2010-4575

GoogleEPSS <= 49%HIGH2010-12-22

The ThemeInstalledInfoBarDelegate::Observe function in browser/extensions/theme_installed_infobar_delegate.cc in Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 does not properly handle incorrect tab interaction by an extension, which...

CVEs:CVE-2010-4575

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
chrome_os affected google
Upstream advisory

CVE-2010-4486

GoogleEPSS <= 49%HIGH2010-12-07

Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to history handling.

CVEs:CVE-2010-4486

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4490

GoogleEPSS <= 49%HIGH2010-12-07

Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via malformed video content that triggers an indexing error.

CVEs:CVE-2010-4490

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4493

GoogleEPSS <= 49%CRITICAL2010-12-07

Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service via vectors related to the handling of mouse dragging events.

CVEs:CVE-2010-4493

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

CVE-2010-4487

GoogleEPSS <= 49%HIGH2010-12-07

Incomplete blacklist vulnerability in Google Chrome before 8.0.552.215 on Linux and Mac OS X allows remote attackers to have an unspecified impact via a "dangerous file."

CVEs:CVE-2010-4487

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4488

GoogleEPSS <= 49%HIGH2010-12-07

Google Chrome before 8.0.552.215 does not properly handle HTTP proxy authentication, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

CVEs:CVE-2010-4488

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4489

GoogleEPSS <= 49%HIGH2010-12-07

libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebM video. NOTE: this vulnerability exists because of a regression.

CVEs:CVE-2010-4489

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4483

GoogleEPSS <= 49%MEDIUM2010-12-07

Google Chrome before 8.0.552.215 does not properly restrict read access to videos derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via a crafted web site.

CVEs:CVE-2010-4483

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4482

GoogleEPSS <= 49%MEDIUM2010-12-07

Unspecified vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to bypass the pop-up blocker via unknown vectors.

CVEs:CVE-2010-4482

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4491

GoogleEPSS <= 49%HIGH2010-12-07

Google Chrome before 8.0.552.215 does not properly restrict privileged extensions, which allows remote attackers to cause a denial of service (memory corruption) via a crafted extension.

CVEs:CVE-2010-4491

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4484

GoogleEPSS <= 49%HIGH2010-12-07

Google Chrome before 8.0.552.215 does not properly handle HTML5 databases, which allows attackers to cause a denial of service (application crash) via unspecified vectors.

CVEs:CVE-2010-4484

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2010-4485

GoogleEPSS <= 49%HIGH2010-12-07

Google Chrome before 8.0.552.215 does not properly restrict the generation of file dialogs, which allows remote attackers to cause a denial of service (reduced usability and possible application crash) via a crafted web site.

CVEs:CVE-2010-4485

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.