CVE-2010-4578
published 2010-12-22CVE-2010-4578: Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of…
PriorityP429high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.65%
74.1th percentile
Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| chrome | < 8.0.552.224 | 8.0.552.224 | |
| chrome_os | < 8.0.552.343 | 8.0.552.343 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2011-08-23
CVE-2010-1824 WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: Multiple security vulnerabilities were fixed in WebKit.
A large number of security issues were discovered in the WebKit browser and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of
service attacks, and arbitrary code execution.
Instructions: After a standard system update you need to restart any applications that
use WebKit, such as Epiphany and Midori, to make all the necessary changes.
Red Hat
WebKit: Stale SVG pointer in Cursors DOM
vendor_redhat·2010-12-13·CVSS 7.5
CVE-2010-4578 [HIGH] WebKit: Stale SVG pointer in Cursors DOM
WebKit: Stale SVG pointer in Cursors DOM
Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."
Package: webkitgtk (Red Hat Enterprise Linux Extended Update Support 6.0) - Will not fix
GHSA
GHSA-jj76-mr38-79x4: Google Chrome before 8
ghsa_unreviewed·2022-05-13
CVE-2010-4578 [HIGH] GHSA-jj76-mr38-79x4: Google Chrome before 8
Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4492 CVE-2010-4493 CVE-2011-0482 CVE-2010-4199 CVE-2010-4578 CVE-2010-4040 CVE-2011-0778 CVE-2010-2901 CVE-2010-4042 webkitgtk various flaws [fedora-13]
bugzilla·2011-02-09·CVSS 10.0
CVE-2010-4492 [CRITICAL] CVE-2010-4492 CVE-2010-4493 CVE-2011-0482 CVE-2010-4199 CVE-2010-4578 CVE-2010-4040 CVE-2011-0778 CVE-2010-2901 CVE-2010-4042 webkitgtk various flaws [fedora-13]
CVE-2010-4492 CVE-2010-4493 CVE-2011-0482 CVE-2010-4199 CVE-2010-4578 CVE-2010-4040 CVE-2011-0778 CVE-2010-2901 CVE-2010-4042 webkitgtk various flaws [fedora-13]
fedora-13 tracking bug for webkitgtk: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-4493
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=676201,676202
---
Adding parent bug CVE-2011-0482
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=676201,676202,676203
---
Adding parent bug CVE-2010-4199
New bodhi update url:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2010-4578 WebKit: Stale SVG pointer in Cursors DOM
bugzilla·2011-02-09·CVSS 7.5
CVE-2010-4578 [HIGH] CVE-2010-4578 WebKit: Stale SVG pointer in Cursors DOM
CVE-2010-4578 WebKit: Stale SVG pointer in Cursors DOM
Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343
do not properly perform cursor handling, which allows remote
attackers to cause a denial of service or possibly have unspecified
other impact via unknown vectors that lead to "stale pointers."
References:
http://code.google.com/p/chromium/issues/detail?id=64959
http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.html
http://www.gentoo.org/security/en/glsa/glsa-201012-01.xml
http://www.securityfocus.com/bid/45390
http://secunia.com/advisories/42648
This is fixed in webkitgtk 1.2.7
Discussion:
Created webkitgtk tracking bugs for this issue
Affects: fedora-13 [bug 676213]
http://code.google.com/p/chromium/issues/detail?id=64959http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlhttp://secunia.com/advisories/42648http://www.debian.org/security/2011/dsa-2188http://www.gentoo.org/security/en/glsa/glsa-201012-01.xmlhttp://www.securityfocus.com/bid/45390https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14323http://code.google.com/p/chromium/issues/detail?id=64959http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlhttp://secunia.com/advisories/42648http://www.debian.org/security/2011/dsa-2188http://www.gentoo.org/security/en/glsa/glsa-201012-01.xmlhttp://www.securityfocus.com/bid/45390https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14323
2010-12-22
Published