5

CVE-2010-1029

Exploit

Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a STYLE element composed of a large number of *> sequences.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AppleSafari Version4.0.4
GoogleChrome Version4.0.249.0
AppleSafari
   AppleiPhone OS
   AppleiPhone OS Version1.0
   AppleiPhone OS Version1.0.0
   AppleiPhone OS Version1.0.1
   AppleiPhone OS Version1.0.1 Update- Editioniphone
   AppleiPhone OS Version1.0.2
   AppleiPhone OS Version1.0.2 Update- Editioniphone
   AppleiPhone OS Version1.1
   AppleiPhone OS Version1.1.0
   AppleiPhone OS Version1.1.0 Update- Editioniphone
   AppleiPhone OS Version1.1.0 Update- Editionipodtouch
   AppleiPhone OS Version1.1.1
   AppleiPhone OS Version1.1.1 Update- Editioniphone
   AppleiPhone OS Version1.1.2
   AppleiPhone OS Version1.1.2 Update- Editioniphone
   AppleiPhone OS Version1.1.2 Update- Editionipodtouch
   AppleiPhone OS Version1.1.3
   AppleiPhone OS Version1.1.3 Update- Editioniphone
   AppleiPhone OS Version1.1.3 Update- Editionipodtouch
   AppleiPhone OS Version1.1.4
   AppleiPhone OS Version1.1.4 Update- Editioniphone
   AppleiPhone OS Version1.1.4 Update- Editionipodtouch
   AppleiPhone OS Version1.1.5
   AppleiPhone OS Version1.1.5 Update- Editioniphone
   AppleiPhone OS Version1.1.5 Update- Editionipodtouch
   AppleiPhone OS Version2.0
   AppleiPhone OS Version2.0.0
   AppleiPhone OS Version2.0.0 Update- Editioniphone
   AppleiPhone OS Version2.0.0 Update- Editionipodtouch
   AppleiPhone OS Version2.0.1
   AppleiPhone OS Version2.0.1 Update- Editioniphone
   AppleiPhone OS Version2.0.1 Update- Editionipodtouch
   AppleiPhone OS Version2.0.2
   AppleiPhone OS Version2.0.2 Update- Editioniphone
   AppleiPhone OS Version2.0.2 Update- Editionipodtouch
   AppleiPhone OS Version2.1
   AppleiPhone OS Version2.1 Update- Editioniphone
   AppleiPhone OS Version2.1 Update- Editionipodtouch
   AppleiPhone OS Version2.1.1
   AppleiPhone OS Version2.2
   AppleiPhone OS Version2.2 Update- Editioniphone
   AppleiPhone OS Version2.2 Update- Editionipodtouch
   AppleiPhone OS Version2.2.1
   AppleiPhone OS Version2.2.1 Update- Editioniphone
   AppleiPhone OS Version2.2.1 Update- Editionipodtouch
   AppleiPhone OS Version3.0
   AppleiPhone OS Version3.0 Update- Editionipodtouch
   AppleiPhone OS Version3.0.1
   AppleiPhone OS Version3.0.1 Update- Editioniphone
   AppleiPhone OS Version3.1.2
   AppleiPhone OS Version3.1.2 Update- Editionipodtouch
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 37.62% 0.968
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P