CVE-2010-1404
published 2010-06-11CVE-2010-1404: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote…
PriorityP337critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
8.73%
94.6th percentile
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG document that contains recursive Use elements, which are not properly handled during page deconstruction.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 4.0.5 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
WebKit: use-after-free vulnerability in handling of SVG documents with multiple 'use' elements (ZDI-CAN-711)
vendor_redhat·2010-06-07·CVSS 9.3
CVE-2010-1404 [CRITICAL] CWE-416 WebKit: use-after-free vulnerability in handling of SVG documents with multiple 'use' elements (ZDI-CAN-711)
WebKit: use-after-free vulnerability in handling of SVG documents with multiple 'use' elements (ZDI-CAN-711)
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG document that contains recursive Use elements, which are not properly handled during page deconstruction.
Package: qt (Red Hat Enterprise Linux 6) - Will not fix
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
GHSA
GHSA-jc34-6m5q-52fv: Use-after-free vulnerability in WebKit in Apple Safari before 5
ghsa_unreviewed·2022-05-02
CVE-2010-1404 [HIGH] GHSA-jc34-6m5q-52fv: Use-after-free vulnerability in WebKit in Apple Safari before 5
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG document that contains recursive Use elements, which are not properly handled during page deconstruction.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40105http://secunia.com/advisories/40196http://secunia.com/advisories/41856http://secunia.com/advisories/43068http://securitytracker.com/id?1024067http://support.apple.com/kb/HT4196http://support.apple.com/kb/HT4220http://support.apple.com/kb/HT4225http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/archive/1/511718/100/0/threadedhttp://www.securityfocus.com/bid/40620http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/1373http://www.vupen.com/english/advisories/2010/1512http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552http://www.zerodayinitiative.com/advisories/ZDI-10-096https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7497http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40105http://secunia.com/advisories/40196http://secunia.com/advisories/41856http://secunia.com/advisories/43068http://securitytracker.com/id?1024067http://support.apple.com/kb/HT4196http://support.apple.com/kb/HT4220http://support.apple.com/kb/HT4225http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.securityfocus.com/archive/1/511718/100/0/threadedhttp://www.securityfocus.com/bid/40620http://www.ubuntu.com/usn/USN-1006-1http://www.vupen.com/english/advisories/2010/1373http://www.vupen.com/english/advisories/2010/1512http://www.vupen.com/english/advisories/2010/2722http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0552http://www.zerodayinitiative.com/advisories/ZDI-10-096https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7497
2010-06-11
Published