Lucene search

K
cveAppleCVE-2010-1806
HistorySep 10, 2010 - 7:00 p.m.

CVE-2010-1806

2010-09-1019:00:02
CWE-399
apple
web.nvd.nist.gov
41
cve-2010-1806
apple safari
vulnerability
code execution
denial of service
nvd
run-in styling
object pointers

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.045

Percentile

92.5%

Use-after-free vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via run-in styling in an element, related to object pointers.

Affected configurations

Nvd
Node
applesafariMatch4.0
OR
applesafariMatch4.0.0b
OR
applesafariMatch4.0.1
OR
applesafariMatch4.0.2
OR
applesafariMatch4.0.3
OR
applesafariMatch4.0.4
OR
applesafariMatch4.0.5
OR
applesafariMatch4.1
OR
applesafariMatch5.0
OR
applesafariMatch5.0.1
VendorProductVersionCPE
applesafari5.0cpe:/a:apple:safari:5.0:::
applesafari4.0.4cpe:/a:apple:safari:4.0.4:::
applesafari4.1cpe:/a:apple:safari:4.1:::
applesafari5.0.1cpe:/a:apple:safari:5.0.1:::
applesafari4.0.3cpe:/a:apple:safari:4.0.3:::
applesafari4.0.2cpe:/a:apple:safari:4.0.2:::
applesafari4.0.1cpe:/a:apple:safari:4.0.1:::
applesafari4.0.0bcpe:/a:apple:safari:4.0.0b:::
applesafari4.0cpe:/a:apple:safari:4.0:::
applesafari4.0.5cpe:/a:apple:safari:4.0.5:::

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.045

Percentile

92.5%