CVE-2010-1823
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger use of document APIs such as document.close during parsing, as demonstrated by a Cascading Style Sheets (CSS) file referencing an invalid SVG font, aka rdar problem 8442098.
Vulnerabilidad de usar después de liberar en WebKit en versiones anteriores a la vr65958, como se utiliza en Google Chrome en versiones anteriores a la v6.0.472.59, permite a atacantes remotos provocar una denegación de servicio y posiblemente provocar otros daños a través de vectores de ataque que provocan el uso de las APIs document tal como document.close durante el parseo, como se ha demostrado por un fichero de hojas de estilo en cascada (CSS) referenciando un "font" SVG, también conocido como problema rdar 8442098.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-05-06 CVE Reserved
- 2010-09-24 CVE Published
- 2024-08-07 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-416: Use After Free
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/43068 | Third Party Advisory | |
http://support.apple.com/kb/HT4808 | Third Party Advisory | |
http://support.apple.com/kb/HT4981 | Third Party Advisory | |
http://www.vupen.com/english/advisories/2011/0212 | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7405 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://code.google.com/p/chromium/issues/detail?id=50250 | 2020-07-31 | |
https://bugs.webkit.org/show_bug.cgi?id=44533 | 2020-07-31 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Chrome Search vendor "Google" for product "Chrome" | < 6.0.472.59 Search vendor "Google" for product "Chrome" and version " < 6.0.472.59" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Itunes Search vendor "Apple" for product "Itunes" | < 10.5 Search vendor "Apple" for product "Itunes" and version " < 10.5" | - |
Affected
| ||||||
Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | < 5.0.6 Search vendor "Apple" for product "Safari" and version " < 5.0.6" | - |
Affected
|