cbcvebase.
CVE-2010-1824
published 2010-09-24

CVE-2010-1824: Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari, and Google Chrome before 6.0.472.59, allows remote…

PriorityP338critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.96%
89.3th percentile
Use-after-free vulnerability in WebKit, as used in Apple iTunes before 10.2 on Windows, Apple Safari, and Google Chrome before 6.0.472.59, allows remote attackers to execute arbitrary code or cause a denial of service via vectors related to SVG styles, the DOM tree, and error messages.

Affected

4 ranges
VendorProductVersion rangeFixed in
appleitunes< 10.210.2
googlechrome< 6.0.472.596.0.472.59
webkitgtkwebkitgtk>= 0 < 2.4.8-1ubuntu1~ubuntu14.04.12.4.8-1ubuntu1~ubuntu14.04.1
webkitgtkwebkitgtk>= 0 < 2.4.9-2ubuntu22.4.9-2ubuntu2

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.