CVE-2010-4203
9.8
CRITICAL · CVSS 3.1 · EPSS 4.6% (pctl 91)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.57% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-190 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2010-11-06 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| chrome | |
| redhat | enterprise linux desktop |
| redhat | enterprise linux server |
| redhat | enterprise linux workstation |
| webmproject | libvpx |
References
- http://code.google.com/p/chromium/issues/detail?id=60055
- http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.html
- http://review.webmproject.org/gitweb?p=libvpx.git%3Ba=blob%3Bf=CHANGELOG
- http://review.webmproject.org/gitweb?p=libvpx.git%3Ba=commit%3Bh=09bcc1f710ea65dc158639479288fb1908ff0c53
- http://secunia.com/advisories/42109
- http://secunia.com/advisories/42118
- http://secunia.com/advisories/42690
- http://secunia.com/advisories/42908
- http://security.gentoo.org/glsa/glsa-201101-03.xml
- http://www.vupen.com/english/advisories/2011/0115
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12198
- https://rhn.redhat.com/errata/RHSA-2010-0999.html
- http://code.google.com/p/chromium/issues/detail?id=60055
- http://googlechromereleases.blogspot.com/2010/11/stable-channel-update.html
- http://review.webmproject.org/gitweb?p=libvpx.git%3Ba=blob%3Bf=CHANGELOG
- http://review.webmproject.org/gitweb?p=libvpx.git%3Ba=commit%3Bh=09bcc1f710ea65dc158639479288fb1908ff0c53
- http://secunia.com/advisories/42109
- http://secunia.com/advisories/42118
- http://secunia.com/advisories/42690
- http://secunia.com/advisories/42908
→ the Explorer · watch your stack · NVD