CVE-2010-2901
published 2010-07-28CVE-2010-2901: The rendering implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have…
PriorityP432critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.40%
82.1th percentile
The rendering implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| chrome | < 5.0.375.125 | 5.0.375.125 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2011-08-23
CVE-2010-1824 WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: Multiple security vulnerabilities were fixed in WebKit.
A large number of security issues were discovered in the WebKit browser and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of
service attacks, and arbitrary code execution.
Instructions: After a standard system update you need to restart any applications that
use WebKit, such as Epiphany and Midori, to make all the necessary changes.
Red Hat
WebKit: Memory corruption with crash in RenderObject::containingBlock()
vendor_redhat·2010-07-10·CVSS 10.0
CVE-2010-2901 [CRITICAL] WebKit: Memory corruption with crash in RenderObject::containingBlock()
WebKit: Memory corruption with crash in RenderObject::containingBlock()
The rendering implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Package: webkitgtk (Red Hat Enterprise Linux Extended Update Support 6.0) - Will not fix
GHSA
GHSA-hffv-7jpc-646r: The rendering implementation in Google Chrome before 5
ghsa_unreviewed·2022-05-13
CVE-2010-2901 [HIGH] CWE-119 GHSA-hffv-7jpc-646r: The rendering implementation in Google Chrome before 5
The rendering implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4492 CVE-2010-4493 CVE-2011-0482 CVE-2010-4199 CVE-2010-4578 CVE-2010-4040 CVE-2011-0778 CVE-2010-2901 CVE-2010-4042 webkitgtk various flaws [fedora-13]
bugzilla·2011-02-09·CVSS 10.0
CVE-2010-4492 [CRITICAL] CVE-2010-4492 CVE-2010-4493 CVE-2011-0482 CVE-2010-4199 CVE-2010-4578 CVE-2010-4040 CVE-2011-0778 CVE-2010-2901 CVE-2010-4042 webkitgtk various flaws [fedora-13]
CVE-2010-4492 CVE-2010-4493 CVE-2011-0482 CVE-2010-4199 CVE-2010-4578 CVE-2010-4040 CVE-2011-0778 CVE-2010-2901 CVE-2010-4042 webkitgtk various flaws [fedora-13]
fedora-13 tracking bug for webkitgtk: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-4493
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=676201,676202
---
Adding parent bug CVE-2011-0482
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=676201,676202,676203
---
Adding parent bug CVE-2010-4199
New bodhi update url:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2010-2901 WebKit: Memory corruption with crash in RenderObject::containingBlock()
bugzilla·2011-02-09·CVSS 10.0
CVE-2010-2901 [CRITICAL] CVE-2010-2901 WebKit: Memory corruption with crash in RenderObject::containingBlock()
CVE-2010-2901 WebKit: Memory corruption with crash in RenderObject::containingBlock()
The rendering implementation in Google Chrome before 5.0.375.125
allows remote attackers to cause a denial of service (memory corruption)
or possibly have unspecified other impact via unknown vectors.
References:
http://code.google.com/p/chromium/issues/detail?id=47866
http://googlechromereleases.blogspot.com/2010/07/stable-channel-update_26.html
http://secunia.com/advisories/40743
This is fixed in webkitgtk 1.2.7
Discussion:
Created webkitgtk tracking bugs for this issue
Affects: fedora-13 [bug 676213]
Bugzilla
CVE-2009-2901 CVE-2009-2902 CVE-2009-2693 CVE-2010-1157 tomcat: multiple vulnerabilities [fedora-all]
bugzilla·2010-04-23·CVSS 5.8
CVE-2009-2901 [MEDIUM] CVE-2009-2901 CVE-2009-2902 CVE-2009-2693 CVE-2010-1157 tomcat: multiple vulnerabilities [fedora-all]
CVE-2009-2901 CVE-2009-2902 CVE-2009-2693 CVE-2010-1157 tomcat: multiple vulnerabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
Forr more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=585331
Please note:
http://code.google.com/p/chromium/issues/detail?id=47866http://googlechromereleases.blogspot.com/2010/07/stable-channel-update_26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlhttp://secunia.com/advisories/40743http://www.debian.org/security/2011/dsa-2188https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11997http://code.google.com/p/chromium/issues/detail?id=47866http://googlechromereleases.blogspot.com/2010/07/stable-channel-update_26.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlhttp://secunia.com/advisories/40743http://www.debian.org/security/2011/dsa-2188https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11997
2010-07-28
Published