CVE-2010-4008
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML document.
- Affected products
- Centos, Openoffice, Red Hat, Libxml2, Libxml2-Devel, Libxml2-Doc, Libxml2-Utils, Mingw32-Libxml2
- Google Chrome
- < 7.0.517.44
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 3.1% (87th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2010-11-16
CVE-2010-4008 at NVD
No indexed exploits for CVE-2010-4008 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2010-4008 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.