CVE-2010-3259
- EPSS 0.82%
- Veröffentlicht 07.09.2010 18:00:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass t...
- EPSS 0.44%
- Veröffentlicht 07.09.2010 18:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Google Chrome before 6.0.472.53 does not properly restrict copying to the clipboard, which has unspecified impact and attack vectors.
CVE-2010-3257
- EPSS 12.15%
- Veröffentlicht 07.09.2010 18:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (applicat...
CVE-2010-2954
- EPSS 0.13%
- Veröffentlicht 03.09.2010 20:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The irda_bind function in net/irda/af_irda.c in the Linux kernel before 2.6.36-rc3-next-20100901 does not properly handle failure of the irda_open_tsap function, which allows local users to cause a denial of service (NULL pointer dereference and pani...
CVE-2010-2226
- EPSS 0.11%
- Veröffentlicht 03.09.2010 20:00:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The xfs_swapext function in fs/xfs/xfs_dfrag.c in the Linux kernel before 2.6.35 does not properly check the file descriptors passed to the SWAPEXT ioctl, which allows local users to leverage write access and obtain read access by swapping one file i...
- EPSS 2.3%
- Veröffentlicht 24.08.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Google Chrome before 5.0.375.127, and webkitgtk before 1.2.5, does not properly handle SVG documents, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors related...
- EPSS 0.46%
- Veröffentlicht 24.08.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) Inser...
- EPSS 1.53%
- Veröffentlicht 24.08.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not properly implement the history feature, which might allow remote attackers to spoof the address bar via unspecified vectors.
- EPSS 12.28%
- Veröffentlicht 24.08.2010 20:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, allow remote attackers to execute arbitrary code or cause a denial of servic...
CVE-2010-2806
- EPSS 9.38%
- Veröffentlicht 19.08.2010 18:00:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Array index error in the t42_parse_sfnts function in type42/t42parse.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via negative size values for certain strings i...