Lucene search

K
ubuntucveUbuntu.comUB:CVE-2010-1805
HistorySep 10, 2010 - 12:00 a.m.

CVE-2010-1805

2010-09-1000:00:00
ubuntu.com
ubuntu.com
11

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

5.1%

Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and
5.x before 5.0.2 on Windows allows local users to gain privileges via a
Trojan horse explorer.exe (aka Windows Explorer) program in a directory
containing a file that had been downloaded by Safari.

Notes

Author Note
jdstrand webkit is a fork of khtml from kdelibs. kdelibs5 is farther from it, while qt4-x11 attempts to unify khtml and webkit.
mdeslaur webkitkde is a wrapper around qt4-x11’s webkit.
sbeattie debian claims this is the DLL path attack

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS

0

Percentile

5.1%