CVE-2010-4494
libxml2: double-free in XPath processing code
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
Vulnerabilidad de liberación doble en libxml2 2.7.8 y otras versiones, tal como se utiliza en Google Chrome en versiones anteriores a 8.0.552.215 y otros productos, permite a atacantes remotos provocar una denegación de servicio o posiblemente tener otro impacto no especificado a través de vectores relacionados con el manejo de XPath.
Potential vulnerabilities have been identified with HP Rapid Deployment Pack (RDP) or HP Insight Control Server Deployment. The vulnerabilities could be exploited remotely affecting confidentiality, integrity and availability. Revision 1 of this advisory.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-12-07 CVE Reserved
- 2010-12-07 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-415: Double Free
CAPEC
References (28)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/40775 | Third Party Advisory | |
http://secunia.com/advisories/42472 | Third Party Advisory | |
http://secunia.com/advisories/42721 | Third Party Advisory | |
http://secunia.com/advisories/42762 | Third Party Advisory | |
http://support.apple.com/kb/HT4554 | Third Party Advisory |
|
http://support.apple.com/kb/HT4564 | Third Party Advisory |
|
http://support.apple.com/kb/HT4566 | Broken Link |
|
http://support.apple.com/kb/HT4581 | Third Party Advisory |
|
http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2010/3319 | Third Party Advisory | |
http://www.vupen.com/english/advisories/2010/3336 | Third Party Advisory | |
http://www.vupen.com/english/advisories/2011/0230 | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11916 | Signature |
URL | Date | SRC |
---|---|---|
http://code.google.com/p/chromium/issues/detail?id=63444 | 2024-08-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | < 8.0.552.215 Search vendor "Google" for product "Chrome" and version " < 8.0.552.215" | - |
Affected
| ||||||
Xmlsoft Search vendor "Xmlsoft" | Libxml2 Search vendor "Xmlsoft" for product "Libxml2" | <= 2.7.8 Search vendor "Xmlsoft" for product "Libxml2" and version " <= 2.7.8" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Itunes Search vendor "Apple" for product "Itunes" | < 10.2 Search vendor "Apple" for product "Itunes" and version " < 10.2" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | < 5.0.4 Search vendor "Apple" for product "Safari" and version " < 5.0.4" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Iphone Os Search vendor "Apple" for product "Iphone Os" | < 4.3.0 Search vendor "Apple" for product "Iphone Os" and version " < 4.3.0" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | < 10.6.7 Search vendor "Apple" for product "Mac Os X" and version " < 10.6.7" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 11.2 Search vendor "Opensuse" for product "Opensuse" and version "11.2" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Opensuse Search vendor "Opensuse" for product "Opensuse" | 11.3 Search vendor "Opensuse" for product "Opensuse" and version "11.3" | - |
Affected
| ||||||
Suse Search vendor "Suse" | Suse Linux Enterprise Server Search vendor "Suse" for product "Suse Linux Enterprise Server" | 11 Search vendor "Suse" for product "Suse Linux Enterprise Server" and version "11" | sp1 |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 14 Search vendor "Fedoraproject" for product "Fedora" and version "14" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Desktop Search vendor "Redhat" for product "Enterprise Linux Desktop" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Desktop" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Eus Search vendor "Redhat" for product "Enterprise Linux Eus" | 6.3 Search vendor "Redhat" for product "Enterprise Linux Eus" and version "6.3" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Search vendor "Redhat" for product "Enterprise Linux Server" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Server" and version "6.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Workstation Search vendor "Redhat" for product "Enterprise Linux Workstation" | 6.0 Search vendor "Redhat" for product "Enterprise Linux Workstation" and version "6.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 5.0 Search vendor "Debian" for product "Debian Linux" and version "5.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 6.0 Search vendor "Debian" for product "Debian Linux" and version "6.0" | - |
Affected
| ||||||
Hp Search vendor "Hp" | Insight Control Server Deployment Search vendor "Hp" for product "Insight Control Server Deployment" | * | - |
Affected
| ||||||
Hp Search vendor "Hp" | Rapid Deployment Pack Search vendor "Hp" for product "Rapid Deployment Pack" | * | - |
Affected
| ||||||
Apache Search vendor "Apache" | Openoffice Search vendor "Apache" for product "Openoffice" | >= 2.1.0 <= 2.4.3 Search vendor "Apache" for product "Openoffice" and version " >= 2.1.0 <= 2.4.3" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Openoffice Search vendor "Apache" for product "Openoffice" | >= 3.0.0 < 3.3.0 Search vendor "Apache" for product "Openoffice" and version " >= 3.0.0 < 3.3.0" | - |
Affected
|