4.3
CVE-2010-4008
- EPSS 3.13%
- Veröffentlicht 17.11.2010 01:00:02
- Zuletzt bearbeitet 16.06.2026 23:23:58
- Erkennungen
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 5.0
Debian ≫ Debian Linux Version 6.0
Canonical ≫ Ubuntu Linux Version 6.06 SwEdition lts
Canonical ≫ Ubuntu Linux Version 8.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 9.10
Canonical ≫ Ubuntu Linux Version 10.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 10.10
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Eus Version 6.3
Redhat ≫ Enterprise Linux Workstation Version 6.0
Suse ≫ Suse Linux Enterprise Server Version 10 Update sp3
Suse ≫ Suse Linux Enterprise Server Version 11 Update -
Suse ≫ Suse Linux Enterprise Server Version 11 Update sp1
Apache ≫ Openoffice Version >= 2.0.0 <= 2.4.3
Apache ≫ Openoffice Version >= 3.0.0 < 3.3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.13% | 0.863 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:N/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html
http://secunia.com/advisories/42314
http://support.apple.com/kb/HT4456
http://www.vupen.com/english/advisories/2010/3046
http://marc.info/?l=bugtraq&m=130331363227777&w=2
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html
http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html
http://support.apple.com/kb/HT4581
http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html
http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html
http://support.apple.com/kb/HT4554
http://support.apple.com/kb/HT4566
http://secunia.com/advisories/40775
http://www.vupen.com/english/advisories/2011/0230
http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.html
http://secunia.com/advisories/42109
http://blog.bkis.com/en/libxml2-vulnerability-in-google-chrome-and-apple-safari/
http://code.google.com/p/chromium/issues/detail?id=58731
http://mail.gnome.org/archives/xml/2010-November/msg00015.html
http://marc.info/?l=bugtraq&m=139447903326211&w=2
http://rhn.redhat.com/errata/RHSA-2013-0217.html
http://secunia.com/advisories/42175
http://secunia.com/advisories/42429
http://www.debian.org/security/2010/dsa-2128
http://www.mandriva.com/security/advisories?name=MDVSA-2010:243
http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.html
http://www.redhat.com/support/errata/RHSA-2011-1749.html
http://www.securityfocus.com/bid/44779
http://www.ubuntu.com/usn/USN-1016-1
http://www.vupen.com/english/advisories/2010/3076
http://www.vupen.com/english/advisories/2010/3100
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12148