CVE-2010-4494

Exp

Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

Published: 2010-12-07 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2010-4494 is rated High Exploit Risk (77.7/100): CVSS High severity, with high exploitation likelihood (EPSS 7.53%, 94th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2010-4494

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2010-4494

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-07-02 7.69% 7.53% -0.16%
2 2026-06-15 1.44% 7.69% +6.25%
3 2026-05-12 1.44%

Full EPSS history (15 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2010-4494

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.5 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 6.4 [email protected]

Weakness enumeration for CVE-2010-4494

OS Trackers for CVE-2010-4494

vendor priority summary link
debian not yet assigned CVE-2010-4494 not yet assigned priority: Debian including 1 source packages (libxml2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2010-4494
gentoo high CVE-2010-4494: 1 GLSA(s) (201110-26), 1 atom(s) (dev-libs/libxml2); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2010-4494
redhat low https://access.redhat.com/security/cve/CVE-2010-4494
suse high CVE-2010-4494 severity important: SUSE including 83 source package names (libxml2, libxml2-2, …), 182 product×package rows across 48 product lines (SUSE CaaS Platform 4.0, SUSE Linux Enterprise Desktop 12, … (48 product lines)): Fixed 102, Known Not Affected 80. https://www.suse.com/security/cve/CVE-2010-4494/
ubuntu low CVE-2010-4494 low priority: Ubuntu including 1 source packages (chromium-browser), 6 status rows across 6 suites (dapper, hardy, karmic, lucid, maverick, upstream): DNE 3, released 3. https://ubuntu.com/security/CVE-2010-4494

Affected software / configurations for CVE-2010-4494

Vendor Product Version Raw CPE
google chrome < 8.0.552.215 cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
xmlsoft libxml2 <= 2.7.8 cpe:2.3:a:xmlsoft:libxml2:*:*:*:*:*:*:*:*
apple itunes < 10.2 cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:*
apple safari < 5.0.4 cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
apple iphone_os < 4.3.0 cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
apple mac_os_x < 10.6.7 cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
opensuse opensuse 11.2 cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*
opensuse opensuse 11.3 cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*
suse suse_linux_enterprise_server 11 cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp1:*:*:*:*:*:*
fedoraproject fedora 14 cpe:2.3:o:fedoraproject:fedora:14:*:*:*:*:*:*:*
redhat enterprise_linux_desktop 6.0 cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
redhat enterprise_linux_eus 6.3 cpe:2.3:o:redhat:enterprise_linux_eus:6.3:*:*:*:*:*:*:*
redhat enterprise_linux_server 6.0 cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
redhat enterprise_linux_workstation 6.0 cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
debian debian_linux 5.0 cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*
debian debian_linux 6.0 cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
hp insight_control_server_deployment cpe:2.3:a:hp:insight_control_server_deployment:*:*:*:*:*:*:*:*
hp rapid_deployment_pack cpe:2.3:a:hp:rapid_deployment_pack:*:*:*:*:*:*:*:*
apache openoffice >= 2.1.0, <= 2.4.3 cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:*
apache openoffice >= 3.0.0, < 3.3.0 cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:*

References for CVE-2010-4494

URL Tags
http://code.google.com/p/chromium/issues/detail?id=63444 Exploit Issue Tracking Patch Vendor Advisory
http://googlechromereleases.blogspot.com/2010/12/stable-beta-channel-updates.html Vendor Advisory
http://lists.apple.com/archives/security-announce/2011//Mar/msg00003.html Mailing List Third Party Advisory
http://lists.apple.com/archives/security-announce/2011//Mar/msg00004.html Mailing List Third Party Advisory
http://lists.apple.com/archives/security-announce/2011/Mar/msg00000.html Mailing List Third Party Advisory
http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html Mailing List Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055775.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-04/msg00000.html Third Party Advisory
http://marc.info/?l=bugtraq&m=139447903326211&w=2 Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-0217.html Third Party Advisory
http://secunia.com/advisories/40775 Third Party Advisory
http://secunia.com/advisories/42472 Third Party Advisory
http://secunia.com/advisories/42721 Third Party Advisory
http://secunia.com/advisories/42762 Third Party Advisory
http://support.apple.com/kb/HT4554 Third Party Advisory
http://support.apple.com/kb/HT4564 Third Party Advisory
http://support.apple.com/kb/HT4566 Broken Link
http://support.apple.com/kb/HT4581 Third Party Advisory
http://www.debian.org/security/2010/dsa-2137 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2010:260 Third Party Advisory
http://www.openoffice.org/security/cves/CVE-2010-4008_CVE-2010-4494.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2011-1749.html Third Party Advisory
http://www.vupen.com/english/advisories/2010/3319 Third Party Advisory
http://www.vupen.com/english/advisories/2010/3336 Third Party Advisory
http://www.vupen.com/english/advisories/2011/0230 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11916 Third Party Advisory
cvelogic Threat Intelligence