Lucene search

K
nvd[email protected]NVD:CVE-2010-3116
HistoryAug 24, 2010 - 8:00 p.m.

CVE-2010-3116

2010-08-2420:00:02
CWE-416
web.nvd.nist.gov
6

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.9

Confidence

High

EPSS

0.052

Percentile

93.0%

Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to improper handling of MIME types by plug-ins.

Affected configurations

Nvd
Node
googlechromeRange<5.0.375.127
Node
applesafariRange<4.1.3
OR
applesafariRange5.05.0.3
OR
appleiphone_osRange<4.2
Node
webkitgtkwebkitgtkRange<1.2.6
Node
canonicalubuntu_linuxMatch9.10
OR
canonicalubuntu_linuxMatch10.04-
OR
canonicalubuntu_linuxMatch10.10

References

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.9

Confidence

High

EPSS

0.052

Percentile

93.0%