cbcvebase.
CVE-2010-4494
published 2010-12-07

CVE-2010-4494: Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause…

PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.53%
93.8th percentile
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

Affected

23 ranges
VendorProductVersion rangeFixed in
apacheopenoffice2.1.0 – 2.4.3
apacheopenoffice>= 3.0.0 < 3.3.03.3.0
appleiphone_os< 4.3.04.3.0
appleitunes< 10.210.2
applemac_os_x< 10.6.710.6.7
applesafari< 5.0.45.0.4
debiandebian_linux
debiandebian_linux
debianlibxml2< libxml2 2.7.8.dfsg-2 (bookworm)libxml2 2.7.8.dfsg-2 (bookworm)
fedoraprojectfedora
googlechrome< 8.0.552.2158.0.552.215
opensuseopensuse
opensuseopensuse
redhatenterprise_linux_desktop
redhatenterprise_linux_eus
redhatenterprise_linux_server
redhatenterprise_linux_workstation
susesuse_linux_enterprise_server
xmlsoftlibxml2<= 2.7.8
xmlsoftlibxml2>= 0 < 2.7.8.dfsg-22.7.8.dfsg-2
xmlsoftlibxml2>= 0 < 2.7.8.dfsg-22.7.8.dfsg-2
xmlsoftlibxml2>= 0 < 2.7.8.dfsg-22.7.8.dfsg-2
xmlsoftlibxml2>= 0 < 2.7.8.dfsg-22.7.8.dfsg-2

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.