Lucene search

K
cveMitreCVE-2010-1176
HistoryMar 29, 2010 - 7:30 p.m.

CVE-2010-1176

2010-03-2919:30:00
CWE-94
mitre
web.nvd.nist.gov
23
safari
apple
iphone
os 3.1.3
remote code execution
cve-2010-1176
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

High

EPSS

0.974

Percentile

99.9%

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to an array of long strings, an array of IMG elements with crafted strings in their SRC attributes, a TBODY element with no associated TABLE element, and certain calls to the delete operator and the cloneNode, clearAttributes, and CollectGarbage methods, possibly a related issue to CVE-2009-0075.

Affected configurations

Nvd
Node
applesafari
AND
appleiphone_osMatch3.1.3
OR
appleiphone_osMatch3.1.3-ipodtouch
VendorProductVersionCPE
applesafari*cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
appleiphone_os3.1.3cpe:2.3:o:apple:iphone_os:3.1.3:*:*:*:*:*:*:*
appleiphone_os3.1.3cpe:2.3:o:apple:iphone_os:3.1.3:-:ipodtouch:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.9

Confidence

High

EPSS

0.974

Percentile

99.9%