CVE-2010-1823Use After Free in Google Chrome

CWE-416Use After Free2 documents2 sources
Severity
9.3CRITICALNVD
EPSS
1.9%
top 16.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 24
Latest updateMay 13

Description

Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger use of document APIs such as document.close during parsing, as demonstrated by a Cascading Style Sheets (CSS) file referencing an invalid SVG font, aka rdar problem 8442098.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

NVDgoogle/chrome< 6.0.472.59
NVDapple/itunes< 10.5
NVDapple/safari< 5.0.6

Patches

🔴Vulnerability Details

1
GHSA
GHSA-29qv-h4j6-wvj9: Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 62022-05-13