CVE-2010-1770Code Injection in Google Chrome

CWE-94Code Injection6 documents5 sources
Severity
9.3CRITICALNVD
EPSS
4.2%
top 11.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 13

Description

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document containing a BR element, related to a "type checking issue."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages5 packages

NVDapple/safari4.0.5
NVDgoogle/chrome< 5.0.375.70
NVDopensuse/opensuse11.2, 11.3+1

Also affects: Ubuntu Linux 10.04, 10.04.4, 10.10, 9.10

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r7q2-qf8r-5h57: WebKit in Apple Safari before 52022-05-13
CVEList
CVE-2010-1770: WebKit in Apple Safari before 52010-06-11

📋Vendor Advisories

1
Red Hat
WebKit: type checking vulnerability in handling of text nodes (ZDI-CAN-765)2010-06-07

💬Community

2
Bugzilla
update webkitgtk to 1.2.32010-07-16
Bugzilla
CVE-2010-1770 WebKit: type checking vulnerability in handling of text nodes (ZDI-CAN-765)2010-05-26
CVE-2010-1770 — Code Injection in Google Chrome | cvebase