VDB
CVE-2010-4209
CVE-2010-4209
PUBLISHED
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore/swfstore.swf.
EPSS 4.27% · 90.1th percentile
Risk Scores
EPSS Score
4.27%
90.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | loggerhead | 0, 1.19~bzr479+dfsg-2 |
| Ubuntu:22.04:LTS | loggerhead | 0, 1.19~bzr511-1 |
| Ubuntu:24.04:LTS | loggerhead | 2.0.1+bzr541+ds-2, 0 |
| Ubuntu:16.04:LTS | webgui | 7.10.29-3, 0 |
| Ubuntu:16.04:LTS | loggerhead | 1.19~bzr479+dfsg-1, 0, 1.19~bzr479+dfsg-1ubuntu1 |
| Ubuntu:20.04:LTS | loggerhead | 1.19~bzr479+dfsg-3, 1.19~bzr494-1, 0 |
| Ubuntu:25.10 | loggerhead | *, 0 |
Timeline
- Nov 7, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 17, 2025 EPSS Score
- Mar 22, 2025 EPSS Score
- Apr 6, 2025 EPSS Score
- Apr 7, 2025 EPSS Score
- Apr 9, 2025 EPSS Score
- Apr 10, 2025 EPSS Score
- Apr 11, 2025 EPSS Score
- May 1, 2025 EPSS Score
- May 4, 2025 EPSS Score
References
- https://ubuntu.com/security/CVE-2010-4209 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2010-4209 third-party-advisory