CVE-2010-0663
Summary
| CVE | CVE-2010-0663 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-02-18 18:00:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The ParamTraits<SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not initialize the memory locations that will hold bitmap data, which might allow remote attackers to obtain potentially sensitive information from process memory by providing insufficient data, related to use of a (1) thumbnail database or (2) HTML canvas. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Chrome | 0.2.149.27 | All | All | All | |
| Application | Chrome | 0.2.149.29 | All | All | All | |
| Application | Chrome | 0.2.149.30 | All | All | All | |
| Application | Chrome | 0.2.152.1 | All | All | All | |
| Application | Chrome | 0.2.153.1 | All | All | All | |
| Application | Chrome | 0.3.154.0 | All | All | All | |
| Application | Chrome | 0.3.154.3 | All | All | All | |
| Application | Chrome | 0.4.154.18 | All | All | All | |
| Application | Chrome | 0.4.154.22 | All | All | All | |
| Application | Chrome | 0.4.154.31 | All | All | All | |
| Application | Chrome | 0.4.154.33 | All | All | All | |
| Application | Chrome | 1.0.154.36 | All | All | All | |
| Application | Chrome | 1.0.154.39 | All | All | All | |
| Application | Chrome | 1.0.154.42 | All | All | All | |
| Application | Chrome | 1.0.154.43 | All | All | All | |
| Application | Chrome | 1.0.154.46 | All | All | All | |
| Application | Chrome | 1.0.154.48 | All | All | All | |
| Application | Chrome | 1.0.154.52 | All | All | All | |
| Application | Chrome | 1.0.154.53 | All | All | All | |
| Application | Chrome | 1.0.154.59 | All | All | All | |
| Application | Chrome | 1.0.154.65 | All | All | All | |
| Application | Chrome | 2.0.156.1 | All | All | All | |
| Application | Chrome | 2.0.157.0 | All | All | All | |
| Application | Chrome | 2.0.157.2 | All | All | All | |
| Application | Chrome | 2.0.158.0 | All | All | All | |
| Application | Chrome | 2.0.159.0 | All | All | All | |
| Application | Chrome | 2.0.169.0 | All | All | All | |
| Application | Chrome | 2.0.169.1 | All | All | All | |
| Application | Chrome | 2.0.170.0 | All | All | All | |
| Application | Chrome | 2.0.172 | All | All | All | |
| Application | Chrome | 2.0.172.2 | All | All | All | |
| Application | Chrome | 2.0.172.27 | All | All | All | |
| Application | Chrome | 2.0.172.28 | All | All | All | |
| Application | Chrome | 2.0.172.30 | All | All | All | |
| Application | Chrome | 2.0.172.31 | All | All | All | |
| Application | Chrome | 2.0.172.33 | All | All | All | |
| Application | Chrome | 2.0.172.37 | All | All | All | |
| Application | Chrome | 2.0.172.38 | All | All | All | |
| Application | Chrome | 2.0.172.8 | All | All | All | |
| Application | Chrome | 3.0.182.2 | All | All | All | |
| Application | Chrome | 3.0.190.2 | All | All | All | |
| Application | Chrome | 3.0.193.2 | beta | All | All | |
| Application | Chrome | 3.0.195.21 | All | All | All | |
| Application | Chrome | 3.0.195.24 | All | All | All | |
| Application | Chrome | 3.0.195.32 | All | All | All | |
| Application | Chrome | 3.0.195.33 | All | All | All | |
| Application | Chrome | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Google Chrome Bugs Let Remote Users Execute Arbitrary Code, Deny Service, and Obtain Information. | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| The Chromium Projects: Chromium Security Bugs | af854a3a-2127-422b-91ae-364da2661108 | sites.google.com | Vendor Advisory |
| Google Chrome Releases: Stable Channel Update | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | Patch |
| Issue 31307 - chromium - [MD audit] [RPC] More errors deserializing SkBitmaps!! - An open-source browser project to help move the web forward. - Google Project Hosting | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.