Lucene search

K
cve[email protected]CVE-2010-4008
HistoryNov 17, 2010 - 1:00 a.m.

CVE-2010-4008

2010-11-1701:00:02
CWE-119
web.nvd.nist.gov
43
libxml2
vulnerability
cve-2010-4008
google chrome
apple safari
xpath
denial of service
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

54.4%

libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.

Affected configurations

NVD
Node
googlechromeRange<7.0.517.44
Node
appleitunesRange<10.2
OR
applesafariRange<5.0.4
OR
appleiphone_osRange<4.2
OR
applemac_os_xRange<10.6.7
Node
xmlsoftlibxml2Range<2.7.8
Node
debiandebian_linuxMatch5.0
OR
debiandebian_linuxMatch6.0
Node
canonicalubuntu_linuxMatch6.06lts
OR
canonicalubuntu_linuxMatch8.04lts
OR
canonicalubuntu_linuxMatch9.10
OR
canonicalubuntu_linuxMatch10.04lts
OR
canonicalubuntu_linuxMatch10.10
Node
redhatenterprise_linux_desktopMatch6.0
OR
redhatenterprise_linux_serverMatch6.0
OR
redhatenterprise_linux_server_eusMatch6.3
OR
redhatenterprise_linux_workstationMatch6.0
Node
opensuseopensuseMatch11.1
OR
opensuseopensuseMatch11.2
OR
opensuseopensuseMatch11.3
OR
susesuse_linux_enterprise_serverMatch10sp3
OR
susesuse_linux_enterprise_serverMatch11-
OR
susesuse_linux_enterprise_serverMatch11sp1
Node
apacheopenofficeRange2.0.02.4.3
OR
apacheopenofficeRange3.0.03.3.0
CPENameOperatorVersion
google:chromegoogle chromelt7.0.517.44

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

5.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

54.4%