CVE-2010-4207

Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to charts/assets/charts.swf.

Published: 2010-11-07 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2010-4207 is rated Moderate Risk (49.6/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 2.93%). Core evidence: EPSS rose +2.25% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2010-4207

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-03-04 0.68% 2.93% +2.25%
2 2026-03-01 2.93% 0.68% -2.25%
3 2026-02-04 2.93%

Full EPSS history (34 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2010-4207

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2010-4207

OS Trackers for CVE-2010-4207

vendor priority summary link
ubuntu medium CVE-2010-4207 medium priority: Ubuntu including 7 source packages (jifty, loggerhead, …), 252 status rows across 36 suites (artful, bionic, cosmic, dapper, disco, eoan, focal, groovy, hardy, hirsute, impish, jammy, karmic, kinetic, lucid, lunar, mantic, maverick, natty, noble, oneiric, oracular, plucky, precise, quantal, questing, raring, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): DNE 120 (5 distinct statuses). https://ubuntu.com/security/CVE-2010-4207

Affected software / configurations for CVE-2010-4207

Vendor Product Version Raw CPE
yahoo yui 2.4.0 cpe:2.3:a:yahoo:yui:2.4.0:*:*:*:*:*:*:*
yahoo yui 2.5.0 cpe:2.3:a:yahoo:yui:2.5.0:*:*:*:*:*:*:*
yahoo yui 2.5.1 cpe:2.3:a:yahoo:yui:2.5.1:*:*:*:*:*:*:*
yahoo yui 2.5.2 cpe:2.3:a:yahoo:yui:2.5.2:*:*:*:*:*:*:*
yahoo yui 2.6.0 cpe:2.3:a:yahoo:yui:2.6.0:*:*:*:*:*:*:*
yahoo yui 2.7.0 cpe:2.3:a:yahoo:yui:2.7.0:*:*:*:*:*:*:*
yahoo yui 2.8.0 cpe:2.3:a:yahoo:yui:2.8.0:*:*:*:*:*:*:*
yahoo yui 2.8.1 cpe:2.3:a:yahoo:yui:2.8.1:*:*:*:*:*:*:*

References for CVE-2010-4207

URL Tags
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050813.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050820.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050830.html
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00005.html
http://moodle.org/mod/forum/discuss.php?d=160910
http://secunia.com/advisories/41955 Vendor Advisory
http://secunia.com/advisories/42271
http://www.bugzilla.org/security/3.2.8/
http://www.openwall.com/lists/oss-security/2010/11/07/1
http://www.securityfocus.com/archive/1/514622
http://www.securityfocus.com/bid/44420
http://www.securitytracker.com/id?1024683
http://www.vupen.com/english/advisories/2010/2878 Vendor Advisory
http://www.vupen.com/english/advisories/2010/2975
http://yuilibrary.com/support/2.8.2/ Patch Vendor Advisory
cvelogic Threat Intelligence