cbcvebase.
CVE-2010-2900
published 2010-07-28

CVE-2010-2900: Google Chrome before 5.0.375.125 does not properly handle a large canvas, which has unspecified impact and remote attack vectors.

PriorityP427critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
1.03%
60.3th percentile
Google Chrome before 5.0.375.125 does not properly handle a large canvas, which has unspecified impact and remote attack vectors.

Affected

3 ranges
VendorProductVersion rangeFixed in
googlechrome< 5.0.375.1255.0.375.125
webkitgtkwebkitgtk>= 0 < 2.4.8-1ubuntu1~ubuntu14.04.12.4.8-1ubuntu1~ubuntu14.04.1
webkitgtkwebkitgtk>= 0 < 2.4.9-2ubuntu22.4.9-2ubuntu2

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.