CVE-2010-4494

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
googlechrome
𝑥
< 8.0.552.215
xmlsoftlibxml2
𝑥
≤ 2.7.8
appleitunes
𝑥
< 10.2
applesafari
𝑥
< 5.0.4
appleiphone_os
𝑥
< 4.3.0
applemac_os_x
𝑥
< 10.6.7
opensuseopensuse
11.2
opensuseopensuse
11.3
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_eus
6.3
redhatenterprise_linux_server
6.0
redhatenterprise_linux_workstation
6.0
debiandebian_linux
5.0
debiandebian_linux
6.0
hpinsight_control_server_deployment
*
hprapid_deployment_pack
*
apacheopenoffice
2.1.0 ≤
𝑥
≤ 2.4.3
apacheopenoffice
3.0.0 ≤
𝑥
< 3.3.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libxml2
bullseye
2.9.10+dfsg-6.7+deb11u4
fixed
bullseye (security)
2.9.10+dfsg-6.7+deb11u5
fixed
bookworm
2.9.14+dfsg-1.3~deb12u1
fixed
sid
2.12.7+dfsg+really2.9.14-0.1
fixed
trixie
2.12.7+dfsg+really2.9.14-0.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
maverick
Fixed 8.0.552.215~r67652-0ubuntu0.10.10.1
released
lucid
Fixed 8.0.552.215~r67652-0ubuntu0.10.04.1
released
karmic
dne
hardy
dne
dapper
dne
References