CVE-2010-1824
published 2010-09-24CVE-2010-1824: Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari, and Google Chrome before 6.0.472.59, allows remote…
PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.96%
89.3th percentile
Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari, and Google Chrome before 6.0.472.59, allows remote attackers to execute arbitrary code or cause a denial of service via vectors related to SVG styles, the DOM tree, and error messages.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | itunes | < 10.2 | 10.2 |
| chrome | < 6.0.472.59 | 6.0.472.59 | |
| webkitgtk | webkitgtk | >= 0 < 2.4.8-1ubuntu1~ubuntu14.04.1 | 2.4.8-1ubuntu1~ubuntu14.04.1 |
| webkitgtk | webkitgtk | >= 0 < 2.4.9-2ubuntu2 | 2.4.9-2ubuntu2 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j66m-f2pj-cwr3: Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10
ghsa_unreviewed·2022-05-13
CVE-2010-1824 [HIGH] CWE-416 GHSA-j66m-f2pj-cwr3: Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10
Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari, and Google Chrome before 6.0.472.59, allows remote attackers to execute arbitrary code or cause a denial of service via vectors related to SVG styles, the DOM tree, and error messages.
OSV
CVE-2010-1824: Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10
osv·2010-09-24·CVSS 9.3
CVE-2010-1824 [CRITICAL] CVE-2010-1824: Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10
Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari, and Google Chrome before 6.0.472.59, allows remote attackers to execute arbitrary code or cause a denial of service via vectors related to SVG styles, the DOM tree, and error messages.
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2011-08-23
CVE-2010-1824 WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: Multiple security vulnerabilities were fixed in WebKit.
A large number of security issues were discovered in the WebKit browser and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of
service attacks, and arbitrary code execution.
Instructions: After a standard system update you need to restart any applications that
use WebKit, such as Epiphany and Midori, to make all the necessary changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code.google.com/p/chromium/issues/detail?id=50712http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_14.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/43068http://support.apple.com/kb/HT4554http://support.apple.com/kb/HT4566http://www.vupen.com/english/advisories/2011/0212http://www.zerodayinitiative.com/advisories/ZDI-11-095https://bugs.webkit.org/show_bug.cgi?id=43260https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7151http://code.google.com/p/chromium/issues/detail?id=50712http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_14.htmlhttp://lists.apple.com/archives/security-announce/2011/Mar/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/43068http://support.apple.com/kb/HT4554http://support.apple.com/kb/HT4566http://www.vupen.com/english/advisories/2011/0212http://www.zerodayinitiative.com/advisories/ZDI-11-095https://bugs.webkit.org/show_bug.cgi?id=43260https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7151
2010-09-24
Published