Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-1029
HistoryMar 19, 2010 - 12:00 a.m.

CVE-2010-1029

2010-03-1900:00:00
ubuntu.com
ubuntu.com
15

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.899

Percentile

98.8%

Stack consumption vulnerability in the WebCore::CSSSelector function in
WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone
OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to
cause a denial of service (application crash) or possibly execute arbitrary
code via a STYLE element composed of a large number of *> sequences.

Notes

Author Note
jdstrand webkit is a fork of khtml from kdelibs. kdelibs5 is farther from it, while qt4-x11 attempts to unify khtml and webkit.
mdeslaur webkitkde is a wrapper around qt4-x11’s webkit. looks like it was safari only

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.899

Percentile

98.8%