Lucene search

K
cve[email protected]CVE-2010-1824
HistorySep 24, 2010 - 7:00 p.m.

CVE-2010-1824

2010-09-2419:00:04
CWE-416
web.nvd.nist.gov
53
cve-2010-1824
webkit
apple itunes
windows
apple safari
google chrome
svg styles
dom tree
error messages
remote attackers
arbitrary code
denial of service
vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.9 High

AI Score

Confidence

High

0.038 Low

EPSS

Percentile

91.9%

Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari, and Google Chrome before 6.0.472.59, allows remote attackers to execute arbitrary code or cause a denial of service via vectors related to SVG styles, the DOM tree, and error messages.

Affected configurations

NVD
Node
googlechromeRange<6.0.472.59
Node
appleitunesRange<10.2
CPENameOperatorVersion
google:chromegoogle chromelt6.0.472.59

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.9 High

AI Score

Confidence

High

0.038 Low

EPSS

Percentile

91.9%