CVE-2010-1806
published 2010-09-10CVE-2010-1806: Use-after-free vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 allows remote attackers to execute arbitrary code or cause a denial of…
PriorityP335critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.48%
91.9th percentile
Use-after-free vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via run-in styling in an element, related to object pointers.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkit: memory corruption in handling of run-in styling (ZDI-CAN-806)
vendor_redhat·2010-09-07·CVSS 9.3
CVE-2010-1806 [CRITICAL] webkit: memory corruption in handling of run-in styling (ZDI-CAN-806)
webkit: memory corruption in handling of run-in styling (ZDI-CAN-806)
Use-after-free vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via run-in styling in an element, related to object pointers.
Package: webkitgtk (Red Hat Enterprise Linux 6) - Will not fix
GHSA
GHSA-3wh4-59gj-xv6c: Use-after-free vulnerability in Apple Safari 4
ghsa_unreviewed·2022-05-17
CVE-2010-1806 [HIGH] GHSA-3wh4-59gj-xv6c: Use-after-free vulnerability in Apple Safari 4
Use-after-free vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via run-in styling in an element, related to object pointers.
Suricata
GPL EXPLOIT unicode directory traversal attempt
suricata·2010-09-23
CVE-2000-0884 GPL EXPLOIT unicode directory traversal attempt
GPL EXPLOIT unicode directory traversal attempt
Rule: alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"GPL EXPLOIT unicode directory traversal attempt"; flow:established,to_server; content:"/..%c1%1c../"; nocase; reference:bugtraq,1806; reference:cve,2000-0884; reference:nessus,10537; classtype:web-application-attack; sid:2100982; rev:14; metadata:created_at 2010_09_23, cve CVE_2000_0884, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2024_11_26, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_technique_id T1083, mitre_technique_name File_And_Directory_Discovery; target:dest_ip;)
Suricata
GPL EXPLOIT unicode directory traversal attempt
suricata·2010-09-23
CVE-2000-0884 GPL EXPLOIT unicode directory traversal attempt
GPL EXPLOIT unicode directory traversal attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"GPL EXPLOIT unicode directory traversal attempt"; flow:established,to_server; http.uri.raw; content:"/..%c0%af../"; nocase; reference:bugtraq,1806; reference:cve,2000-0884; reference:nessus,10537; classtype:web-application-attack; sid:2100981; rev:17; metadata:created_at 2010_09_23, cve CVE_2000_0884, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2024_11_26, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_technique_id T1083, mitre_technique_name File_And_Directory_Discovery; target:dest_ip;)
Suricata
GPL EXPLOIT unicode directory traversal attempt
suricata·2010-09-23
CVE-2000-0884 GPL EXPLOIT unicode directory traversal attempt
GPL EXPLOIT unicode directory traversal attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"GPL EXPLOIT unicode directory traversal attempt"; flow:established,to_server; http.uri.raw; content:"/..%c1%9c../"; reference:bugtraq,1806; reference:cve,2000-0884; reference:nessus,10537; classtype:web-application-attack; sid:2100983; rev:22; metadata:created_at 2010_09_23, cve CVE_2000_0884, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2024_11_26, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_technique_id T1083, mitre_technique_name File_And_Directory_Discovery; target:dest_ip;)
Suricata
GPL ATTACK_RESPONSE file copied ok
suricata·2010-09-23
CVE-2000-0884 GPL ATTACK_RESPONSE file copied ok
GPL ATTACK_RESPONSE file copied ok
Rule: alert http $HTTP_SERVERS any -> $EXTERNAL_NET any (msg:"GPL ATTACK_RESPONSE file copied ok"; flow:established,to_client; file.data; content:"1 file|28|s|29| copied"; nocase; reference:bugtraq,1806; reference:cve,2000-0884; classtype:bad-unknown; sid:2100497; rev:15; metadata:created_at 2010_09_23, cve CVE_2000_0884, confidence Medium, signature_severity Informational, updated_at 2024_04_03;)
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010//Sep/msg00001.htmlhttp://secunia.com/advisories/42314http://support.apple.com/kb/HT4333http://support.apple.com/kb/HT4456http://www.securityfocus.com/bid/43049http://www.vupen.com/english/advisories/2010/3046https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11729http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010//Sep/msg00001.htmlhttp://secunia.com/advisories/42314http://support.apple.com/kb/HT4333http://support.apple.com/kb/HT4456http://www.securityfocus.com/bid/43049http://www.vupen.com/english/advisories/2010/3046https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11729
2010-09-10
Published