CVE-2010-4203Integer Overflow or Wraparound in Google Chrome

Severity
9.8CRITICALNVD
EPSS
8.1%
top 7.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6
Latest updateMay 13

Description

WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

🔴Vulnerability Details

3
GHSA
GHSA-v9gv-2chp-hf2r: WebM libvpx (aka the VP8 Codec SDK) before 02022-05-13
OSV
CVE-2010-4203: WebM libvpx (aka the VP8 Codec SDK) before 02010-11-06
CVEList
CVE-2010-4203: WebM libvpx (aka the VP8 Codec SDK) before 02010-11-05

📋Vendor Advisories

3
Ubuntu
libvpx vulnerability2010-11-10
Red Hat
libvpx: memory corruption flaw2010-11-04
Debian
CVE-2010-4203: libvpx - WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome befor...2010

💬Community

2
Bugzilla
CVE-2010-4203 libvpx: memory corruption flaw [fedora-all]2010-11-11
Bugzilla
CVE-2010-4203 libvpx: memory corruption flaw2010-11-09
CVE-2010-4203 — Integer Overflow or Wraparound | cvebase