CVE-2010-1769
published 2010-06-18CVE-2010-1769: WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, accesses out-of-bounds memory during the handling of tables…
PriorityP340critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.92%
93.4th percentile
WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, accesses out-of-bounds memory during the handling of tables, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, a different vulnerability than CVE-2010-1387 and CVE-2010-1763.
Affected
87 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 3.2.1 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | itunes | <= 9.0.3 | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
WebKit: use-after-free vulnerability in JavaScriptCore during page transitions
vendor_redhat·2010-06-07·CVSS 9.3
CVE-2010-1387 [CRITICAL] CWE-416 WebKit: use-after-free vulnerability in JavaScriptCore during page transitions
WebKit: use-after-free vulnerability in JavaScriptCore during page transitions
Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.
Package: qt (Red Hat Enterprise Linux 6) - Not affected
Package: webkitgtk (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-59px-m78w-3rc3: Unspecified vulnerability in WebKit in Apple iTunes before 9
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2010-1763 [CRITICAL] GHSA-59px-m78w-3rc3: Unspecified vulnerability in WebKit in Apple iTunes before 9
Unspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows has unknown impact and attack vectors, a different vulnerability than CVE-2010-1387 and CVE-2010-1769.
GHSA
GHSA-hpch-jc47-w6qm: WebKit in Apple iTunes before 9
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2010-1769 [CRITICAL] GHSA-hpch-jc47-w6qm: WebKit in Apple iTunes before 9
WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, accesses out-of-bounds memory during the handling of tables, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, a different vulnerability than CVE-2010-1387 and CVE-2010-1763.
GHSA
GHSA-3jqw-5j52-c5fj: Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9
ghsa_unreviewed·2022-05-02·CVSS 10.0
CVE-2010-1387 [CRITICAL] GHSA-3jqw-5j52-c5fj: Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9
Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40196http://secunia.com/advisories/43068http://securitytracker.com/id?1024108http://support.apple.com/kb/HT4220http://support.apple.com/kb/HT4225http://www.securityfocus.com/bid/41016http://www.vupen.com/english/advisories/2010/1512http://www.vupen.com/english/advisories/2011/0212https://exchange.xforce.ibmcloud.com/vulnerabilities/59508https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7178http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/40196http://secunia.com/advisories/43068http://securitytracker.com/id?1024108http://support.apple.com/kb/HT4220http://support.apple.com/kb/HT4225http://www.securityfocus.com/bid/41016http://www.vupen.com/english/advisories/2010/1512http://www.vupen.com/english/advisories/2011/0212https://exchange.xforce.ibmcloud.com/vulnerabilities/59508https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7178
2010-06-18
Published