VDB
CVE-2010-1772
CVE-2010-1772
PUBLISHED
CVSS 8.800000190734863 HIGH
Use-after-free vulnerability in page/Geolocation.cpp in WebCore in WebKit before r59859, as used in Google Chrome before 5.0.375.70, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site, related to failure to stop timers associated with geolocation upon deletion of a document.
EPSS 1.97% · 79.5th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
1.97%
79.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chrome | 0 | |
| opensuse | opensuse | 11.3, 11.2 |
| fedoraproject | fedora | 13, 12 |
| redhat | enterprise_linux | 6.0 |
| n/a | n/a | * |
| canonical | ubuntu_linux | 10.10, 10.04, 9.10 |
Timeline
- Sep 24, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 5, 2023 EPSS Score
- May 28, 2023 EPSS Score
- Jul 20, 2023 EPSS Score
References
- ADV-2010-2722 vdb
- 43068 third-party-advisory
- oval:org.mitre.oval:def:11661 vdb
- http://googlechromereleases.blogspot.com/2010/06/stable-channel-update.html url
- MDVSA-2011:039 vendor-advisory
- SUSE-SR:2011:002 vendor-advisory
- ADV-2011-0552 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2010-1772 advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044023.html url
- http://www.ubuntu.com/usn/USN-1006-1 url
- http://lists.fedoraproject.org/pipermail/package-announce/2010-July/044031.html mailing_list
- http://secunia.com/advisories/40557 technical
- http://www.vupen.com/english/advisories/2010/1801 technical
- https://bugzilla.redhat.com/show_bug.cgi?id=596498 issue
- http://code.google.com/p/chromium/issues/detail?id=44868 exploit
- http://secunia.com/advisories/40072 technical
- http://secunia.com/advisories/41856 technical
- http://trac.webkit.org/changeset/59859 mailing_list
- http://www.vupen.com/english/advisories/2011/0212 technical
- https://bugs.webkit.org/show_bug.cgi?id=39388 technical