4.3
CVSSv2

CVE-2010-1131

Published: 27/03/2010 Updated: 08/06/2010
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, allows remote malicious users to cause a denial of service (application crash) via an HTML document composed of many successive occurrences of the <object> substring.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 4.0.5

Vendor Advisories

Debian Bug report logs - #599830 Multiple security issues Package: webkit; Maintainer for webkit is (unknown); Reported by: Moritz Muehlenhoff &lt;jmm@debianorg&gt; Date: Mon, 11 Oct 2010 17:51:09 UTC Severity: grave Tags: security Fixed in version 125-1 Done: Gustavo Noronha Silva &lt;kov@debianorg&gt; Bug is archived N ...

Exploits

&lt;html&gt; &lt;--------------------- Crash Report Problem Event Name: APPCRASH Application Name: Safariexe Application Version: 531227 Application Timestamp: 4b8f94fa Fault Module Name: JavaScriptCoredll Fault Module Version: 531225 Fault Module Timestamp: 4b8cb88c Exception Code: c00000fd ...
&lt;?php /*************************************************************************** [TITLE]: SAFARI APPLE 405 (object tag) (JavaScriptCoredll) DoS (Crash) [OS]: WINDOWS XP SP3 [DOWNLOAD]: wwwapplecom/es/safari/download/ [AUTHOR]: 3lkt3F0k4 [CONTACT]: 3lkt3F0k4[i_love_spam]gmail[i_love_spam]com -------------------------CRASH DUMP SNI ...