CVE-2010-2648
Last modified
CVE-2010-2648 is a vulnerability of currently unknown severity. The implementation of the Unicode Bidirectional Algorithm (aka Bidi algorithm or UBA) in Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.. EPSS estimates a 2.05% chance of exploitation in the next 30 days.
Description
The implementation of the Unicode Bidirectional Algorithm (aka Bidi algorithm or UBA) in Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chrome | < 5.0.375.99 | |
| Opensuse | Opensuse | 11.3 |
| Canonical | Ubuntu Linux | 9.10 |
| Canonical | Ubuntu Linux | 10.04 |
| Canonical | Ubuntu Linux | 10.10 |
References
- http://code.google.com/p/chromium/issues/detail?id=44424Issue Tracking, Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/41856Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:039Third Party Advisory
- http://www.ubuntu.com/usn/USN-1006-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2722Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0552Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=44424Issue Tracking, Patch, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/41856Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:039Third Party Advisory
- http://www.ubuntu.com/usn/USN-1006-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2722Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0552Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-2648?
How severe is CVE-2010-2648?
How do I fix CVE-2010-2648?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-2642Heap-based buffer overflow in the AFM font parser in the dvi…
- CVE-2010-2643Integer overflow in the TFM font parser in the dvi-backend c…
- CVE-2010-2644IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 b…
- CVE-2010-2645Unspecified vulnerability in Google Chrome before 5.0.375.99…
- CVE-2010-2646Google Chrome before 5.0.375.99 does not properly isolate sa…
- CVE-2010-2647Google Chrome before 5.0.375.99 allows remote attackers to c…
- CVE-2010-2649Unspecified vulnerability in Google Chrome before 5.0.375.99…
- CVE-2010-2650Unspecified vulnerability in Google Chrome before 5.0.375.99…
- CVE-2010-2651The Cascading Style Sheets (CSS) implementation in Google Ch…
- CVE-2010-2652Google Chrome before 5.0.375.99 does not properly implement …
- CVE-2010-2653Race condition in the hvc_close function in drivers/char/hvc…
- CVE-2010-2654Multiple cross-site scripting (XSS) vulnerabilities on the I…
Are you affected by CVE-2010-2648?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
