Vulnerability Name: | CVE-2010-4199 (CCN-63007) | ||||||||||||||||
Assigned: | 2010-11-04 | ||||||||||||||||
Published: | 2010-11-04 | ||||||||||||||||
Updated: | 2020-07-31 | ||||||||||||||||
Summary: | Google Chrome before 7.0.517.44 does not properly perform a cast of an unspecified variable during processing of an SVG use element, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SVG document. | ||||||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
| ||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||
Vulnerability Consequences: | Other | ||||||||||||||||
References: | Source: CONFIRM Type: Exploit, Issue Tracking, Mailing List, Vendor Advisory http://code.google.com/p/chromium/issues/detail?id=58657 Source: MITRE Type: CNA CVE-2010-4199 Source: CCN Type: Google Chrome Releases Web site Stable Channel Update Source: CONFIRM Type: Release Notes, Vendor Advisory http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.html Source: CCN Type: DSA 2188-1 webkit security update Source: CCN Type: SA42109 Google Chrome Multiple Vulnerabilities Source: SECUNIA Type: Broken Link 42109 Source: CCN Type: SA43688 Debian webkit Multiple Vulnerabilities Source: DEBIAN Type: Third Party Advisory DSA-2188 Source: DEBIAN Type: DSA-2188 webkit -- several vulnerabilities Source: CCN Type: OSVDB ID: 69165 Google Chrome SVG Document use Element Variable Casting Weakness Remote DoS Source: CCN Type: BID-44646 Google Chrome prior to 7.0.517.44 Multiple Security Vulnerabilities Source: XF Type: UNKNOWN chrome-bad-cast-unspecified(63007) Source: OVAL Type: Third Party Advisory oval:org.mitre.oval:def:11429 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |