Lucene search

K
cve[email protected]CVE-2010-4494
HistoryDec 07, 2010 - 9:00 p.m.

CVE-2010-4494

2010-12-0721:00:09
CWE-415
web.nvd.nist.gov
93
cve-2010-4494
double free
libxml2
denial of service
remote attackers
xpath handling

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.8%

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

Affected configurations

NVD
Node
googlechromeRange<8.0.552.215
Node
xmlsoftlibxml2Range2.7.8
Node
appleitunesRange<10.2
OR
applesafariRange<5.0.4
OR
appleiphone_osRange<4.3.0
OR
applemac_os_xRange<10.6.7
Node
opensuseopensuseMatch11.2
OR
opensuseopensuseMatch11.3
OR
susesuse_linux_enterprise_serverMatch11sp1
Node
fedoraprojectfedoraMatch14
Node
redhatenterprise_linux_desktopMatch6.0
OR
redhatenterprise_linux_eusMatch6.3
OR
redhatenterprise_linux_serverMatch6.0
OR
redhatenterprise_linux_workstationMatch6.0
Node
debiandebian_linuxMatch5.0
OR
debiandebian_linuxMatch6.0
Node
hpinsight_control_server_deployment
OR
hprapid_deployment_pack
Node
apacheopenofficeRange2.1.02.4.3
OR
apacheopenofficeRange3.0.03.3.0

References

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.8%