CVE-2010-2302 describes a critical use-after-free vulnerability in WebKit's WebCore component, specifically affecting Google Chrome before version 5.0.375.70, as well as OpenSUSE and SUSE products. This flaw allows remote attackers to trigger memory corruption, leading to a denial of service or potentially arbitrary code execution, by manipulating remote fonts within shadow DOM trees. With a CVSS score of 10.0, this vulnerability is highly severe, requiring no authentication and having low attack complexity, making it easily exploitable with full confidentiality, integrity, and availability impacts. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) is available and there's no evidence of active exploitation, its high FAUCET Risk Score of 86/100 indicates significant potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.375.70CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
11.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:* | ||
11.3CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:o:suse:suse_linux_enterprise_desktop:10:sp3:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:suse:suse_linux_enterprise_desktop:11:sp1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.