CVE-2010-4577
- EPSS 4.27%
- Veröffentlicht 22.12.2010 01:00:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS...
CVE-2010-4578
- EPSS 1.77%
- Veröffentlicht 22.12.2010 01:00:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale po...
CVE-2010-4344
- EPSS 51.87%
- Veröffentlicht 14.12.2010 16:00:04
- Zuletzt bearbeitet 21.04.2026 20:31:04
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted hea...
CVE-2010-4345
- EPSS 6.51%
- Veröffentlicht 14.12.2010 16:00:04
- Zuletzt bearbeitet 21.04.2026 20:30:40
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory direct...
CVE-2010-3880
- EPSS 0.13%
- Veröffentlicht 10.12.2010 19:00:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message t...
CVE-2010-4492
- EPSS 1.92%
- Veröffentlicht 07.12.2010 21:00:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animations.
CVE-2010-4493
- EPSS 1.58%
- Veröffentlicht 07.12.2010 21:00:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service via vectors related to the handling of mouse dragging events.
CVE-2010-4494
- EPSS 1.44%
- Veröffentlicht 07.12.2010 21:00:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath...
CVE-2010-4180
- EPSS 3.85%
- Veröffentlicht 06.12.2010 21:05:48
- Zuletzt bearbeitet 29.04.2026 01:13:23
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an uninte...
CVE-2010-4080
- EPSS 0.08%
- Veröffentlicht 30.11.2010 22:14:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
The snd_hdsp_hwdep_ioctl function in sound/pci/rme9652/hdsp.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via an SNDRV_HD...