CVE-2010-4578
Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Google Chrome before 8.0.552.224 and Chrome OS before 8.0.552.343 do not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to "stale pointers."
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.65% probability · 75th percentile
- CISA KEV
- Not listed
- Affected
- google/chrome os · google/chrome · debian/debian linux
- Source
- cve@mitre.org
References
- http://code.google.com/p/chromium/issues/detail?id=64959Permissions Required
- http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.htmlVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/42648Vendor Advisory
- http://www.debian.org/security/2011/dsa-2188Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-201012-01.xmlThird Party Advisory
- http://www.securityfocus.com/bid/45390Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14323Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=64959Permissions Required
- http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates_13.htmlVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00005.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/42648Vendor Advisory
- http://www.debian.org/security/2011/dsa-2188Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-201012-01.xmlThird Party Advisory
- http://www.securityfocus.com/bid/45390Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14323Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.