Lucene search

K
cveAppleCVE-2010-0053
HistoryMar 15, 2010 - 2:15 p.m.

CVE-2010-0053

2010-03-1514:15:32
CWE-399
apple
web.nvd.nist.gov
38
cve-2010-0053
webkit
apple safari
remote attack
arbitrary code execution
denial of service
application crash
css
vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.6

Confidence

High

EPSS

0.135

Percentile

95.7%

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the run-in Cascading Style Sheets (CSS) display property.

Affected configurations

Nvd
Node
applesafariRange4.0.4
OR
applesafariMatch4.0
OR
applesafariMatch4.0beta
OR
applesafariMatch4.0.0b
OR
applesafariMatch4.0.1
OR
applesafariMatch4.0.2
OR
applesafariMatch4.0.3
VendorProductVersionCPE
applesafari4.0cpe:/a:apple:safari:4.0:beta::
applesafari4.0.3cpe:/a:apple:safari:4.0.3:::
applesafari4.0.2cpe:/a:apple:safari:4.0.2:::
applesafari4.0.1cpe:/a:apple:safari:4.0.1:::
applesafaricpe:/a:apple:safari::::
applesafari4.0.0bcpe:/a:apple:safari:4.0.0b:::
applesafari4.0cpe:/a:apple:safari:4.0:::

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

8.6

Confidence

High

EPSS

0.135

Percentile

95.7%