CVE-2010-4038
- EPSS 1.67%
- Veröffentlicht 21.10.2010 19:00:04
- Zuletzt bearbeitet 16.06.2026 23:24:01
The Web Sockets implementation in Google Chrome before 7.0.517.41 does not properly handle a shutdown action, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.
CVE-2010-4039
- EPSS 1.32%
- Veröffentlicht 21.10.2010 19:00:04
- Zuletzt bearbeitet 16.06.2026 23:24:02
Google Chrome before 7.0.517.41 on Linux does not properly set the PATH environment variable, which has unspecified impact and attack vectors.
CVE-2010-4040
- EPSS 1.41%
- Veröffentlicht 21.10.2010 19:00:04
- Zuletzt bearbeitet 16.06.2026 23:24:02
Google Chrome before 7.0.517.41 does not properly handle animated GIF images, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted image.
CVE-2010-3729
- EPSS 2.14%
- Veröffentlicht 05.10.2010 18:00:32
- Zuletzt bearbeitet 16.06.2026 23:23:24
The SPDY protocol implementation in Google Chrome before 6.0.472.62 does not properly manage buffers, which might allow remote attackers to execute arbitrary code via unspecified vectors.
CVE-2010-3730
- EPSS 0.8%
- Veröffentlicht 05.10.2010 18:00:32
- Zuletzt bearbeitet 16.06.2026 23:23:24
Google Chrome before 6.0.472.62 does not properly use information about the origin of a document to manage properties, which allows remote attackers to have an unspecified impact via a crafted web site, related to a "property pollution" issue.
CVE-2010-1822
- EPSS 2.18%
- Veröffentlicht 04.10.2010 21:00:03
- Zuletzt bearbeitet 16.06.2026 23:19:24
WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3 and Google Chrome before 6.0.472.62, does not properly perform a cast of an unspecified variable, which allows remote attackers to execute arbitrary code or cause a denial of service...
CVE-2010-1767
- EPSS 0.96%
- Veröffentlicht 24.09.2010 19:00:04
- Zuletzt bearbeitet 16.06.2026 23:19:16
Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows remote attackers to hijack the authentication of unspecified victims via a...
CVE-2010-1772
- EPSS 1.97%
- Veröffentlicht 24.09.2010 19:00:04
- Zuletzt bearbeitet 16.06.2026 23:19:17
Use-after-free vulnerability in page/Geolocation.cpp in WebCore in WebKit before r59859, as used in Google Chrome before 5.0.375.70, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web ...
CVE-2010-1773
- EPSS 2.15%
- Veröffentlicht 24.09.2010 19:00:04
- Zuletzt bearbeitet 16.06.2026 23:19:17
Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70, allows remote attackers to obtain sensitive information, cause a denial of service (memory...
CVE-2010-1823
- EPSS 3.28%
- Veröffentlicht 24.09.2010 19:00:04
- Zuletzt bearbeitet 16.06.2026 23:19:24
Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger use of document APIs such as doc...