CVE-2010-2646
published 2010-07-06CVE-2010-2646: Google Chrome before 5.0.375.99 does not properly isolate sandboxed IFRAME elements, which has unspecified impact and remote attack vectors.
PriorityP423critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
0.85%
54.7th percentile
Google Chrome before 5.0.375.99 does not properly isolate sandboxed IFRAME elements, which has unspecified impact and remote attack vectors.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 5.0.375.99 | 5.0.375.99 | |
| webkitgtk | webkitgtk | >= 0 < 2.4.8-1ubuntu1~ubuntu14.04.1 | 2.4.8-1ubuntu1~ubuntu14.04.1 |
| webkitgtk | webkitgtk | >= 0 < 2.4.9-2ubuntu2 | 2.4.9-2ubuntu2 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wx59-w85q-r62g: Google Chrome before 5
ghsa_unreviewed·2022-05-13
CVE-2010-2646 [HIGH] GHSA-wx59-w85q-r62g: Google Chrome before 5
Google Chrome before 5.0.375.99 does not properly isolate sandboxed IFRAME elements, which has unspecified impact and remote attack vectors.
OSV
CVE-2010-2646: Google Chrome before 5
osv·2010-07-06·CVSS 9.3
CVE-2010-2646 [CRITICAL] CVE-2010-2646: Google Chrome before 5
Google Chrome before 5.0.375.99 does not properly isolate sandboxed IFRAME elements, which has unspecified impact and remote attack vectors.
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2011-08-23
CVE-2010-1824 WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: Multiple security vulnerabilities were fixed in WebKit.
A large number of security issues were discovered in the WebKit browser and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of
service attacks, and arbitrary code execution.
Instructions: After a standard system update you need to restart any applications that
use WebKit, such as Epiphany and Midori, to make all the necessary changes.
No detection rules found.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=42575http://code.google.com/p/chromium/issues/detail?id=42980http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11981http://code.google.com/p/chromium/issues/detail?id=42575http://code.google.com/p/chromium/issues/detail?id=42980http://googlechromereleases.blogspot.com/2010/07/stable-channel-update.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11981
2010-07-06
Published