[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-1939Date: (C)2010-05-13   (M)2023-12-22


Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers improper handling of a deleted window object.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.6
Exploit Score: 4.9
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1023958
SECUNIA-39670
BID-39990
OSVDB-64482
ADV-2010-1097
VU#943165
http://h07.w.interia.pl/Safari.rar
http://reviews.cnet.com/8301-13727_7-20004709-263.html
oval:org.mitre.oval:def:6748

CPE    2
cpe:/a:apple:safari:4.0.5
cpe:/o:microsoft:windows
CWE    1
CWE-399
OVAL    1
oval:org.mitre.oval:def:6748

© SecPod Technologies