CVE-2010-0042Sensitive Information Exposure in Apple Safari

Severity
4.3MEDIUMNVD
EPSS
1.0%
top 23.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 15
Latest updateMay 2

Description

ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF image.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDapple/safari4.0.4+5

Patches

🔴Vulnerability Details

1
GHSA
GHSA-h9x7-6vv2-h94q: ImageIO in Apple Safari before 42022-05-02