7.5
CVE-2010-4494
- EPSS 1.62%
- Published 07.12.2010 21:00:09
- Last modified 11.04.2025 00:51:21
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
Data is provided by the National Vulnerability Database (NVD)
Suse ≫ Suse Linux Enterprise Server Version11 Updatesp1
Fedoraproject ≫ Fedora Version14
Redhat ≫ Enterprise Linux Desktop Version6.0
Redhat ≫ Enterprise Linux Eus Version6.3
Redhat ≫ Enterprise Linux Server Version6.0
Redhat ≫ Enterprise Linux Workstation Version6.0
Debian ≫ Debian Linux Version5.0
Debian ≫ Debian Linux Version6.0
Apache ≫ Openoffice Version >= 2.1.0 <= 2.4.3
Apache ≫ Openoffice Version >= 3.0.0 < 3.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.62% | 0.811 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-415 Double Free
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.