V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2010-4494
DEB
MediumConfirmedExploit available

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remot…

CVSS
4.3
Medium
EPSS
0.01
p80
Published
2010-01-01
Updated
2010-01-01
Description

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

Tags · CWE
CWE-415
Affected products
Chrome < 8.0.552.215
CVSS vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Timeline
2010-01-01
Published
2010-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.014 · p80
Known exploited (KEV)
No
Known exploits — Сканер-ВС
35810
exploitdb · https://www.exploit-db.com/exploits/35810
Enterprise
Affected software
ProductVendorStatus
chromium-browserTracked
libxml2Tracked
libxml2Tracked
mingw32-libxml2Tracked
webkitTracked
chrome*Tracked
debian_linux*Tracked
enterprise_linux_desktop*Tracked
enterprise_linux_eus*Tracked
enterprise_linux_server*Tracked
enterprise_linux_workstation*Tracked
fedora*Tracked
insight_control_server_deployment*Tracked
iphone_os*Tracked
itunes*Tracked
libxml2*Tracked
mac_os_x*Tracked
openoffice*Tracked
opensuse*Tracked
rapid_deployment_pack*Tracked