V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2010-4008
DEB
MediumConfirmedExploit available

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid me…

CVSS
4.3
Medium
EPSS
0.01
p73
Published
2010-01-01
Updated
2010-01-01
Description

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.

Tags · CWE
RCE
CWE-119
CWE-476
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-24
CAPEC-42
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-100
CAPEC-123
Affected products
Chrome < 7.0.517.44
CVSS vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Timeline
2010-01-01
Published
2010-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.008 · p73
Known exploited (KEV)
No
Known exploits — Сканер-ВС
35810
exploitdb · https://www.exploit-db.com/exploits/35810
Enterprise
Affected software
ProductVendorStatus
libxml2Tracked
libxml2Tracked
libxml2Tracked
libxml2Tracked
mingw32-libxml2Tracked
chrome*Tracked
debian_linux*Tracked
enterprise_linux_desktop*Tracked
enterprise_linux_server*Tracked
enterprise_linux_server_eus*Tracked
enterprise_linux_workstation*Tracked
iphone_os*Tracked
itunes*Tracked
libxml2*Tracked
mac_os_x*Tracked
openoffice*Tracked
opensuse*Tracked
safari*Tracked
suse_linux_enterprise_server*Tracked
ubuntu_linux*Tracked