5
CVSSv2

CVE-2010-1029

Published: 19/03/2010 Updated: 23/05/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a STYLE element composed of a large number of *> sequences.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 4.0.4

google chrome 4.0.249.0

apple safari

Exploits

Apple Safari 404 & Google Chrome 40249 CSS style Stack Overflow DoS/PoC Thank you Rad L Sneak <br/><br/>Apple Safari 404 & Google Chrome 40249 CSS style Stack Overflow DoS/PoC Tested on WinXP SP3 and Windows 7 64bit Also works on Apple iPhone Safari Stack Overflow caused by long malformed string inside of <style ...
#!/usr/bin/python # , # dM # MMr # 4MMML # MMMMM xf # "M6MMM MM- # Mh +MM5MMM MMMM # MMM MMMMML MMMMMh # )MMMh ...