9.3
CVSSv2

CVE-2010-1759

Published: 11/06/2010 Updated: 19/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Use-after-free vulnerability in WebKit in Apple Safari prior to 5.0 on Mac OS X 10.5 up to and including 10.6 and Windows, and prior to 4.1 on Mac OS X 10.4, allows remote malicious users to execute arbitrary code or cause a denial of service (application crash) via vectors related to the Node.normalize method.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 4.0.1

apple safari 4.0.0b

apple safari 4.0

apple safari 4.0.3

apple safari 4.0.2

apple safari 4.0.4

apple webkit

apple safari

Exploits

<!-- CVE-2010-1759 webkit normalize bug Tested on Moto Droidx2 running 22 Droidx2 running 23 is vulnerable but exploit fails due to non-executable heap Still working on a way around that :) 21 - 23 emulator The changes needed are documented in the code The emulator is less consistent than the real phone Author: MJ Keith mjkeith[at]ev ...
Proof of concept exploit that demonstrates the Webkit normalize bug for Android version 22 ...