Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2010-1939

Опубликовано: 13 мая 2010
Источник: debian
EPSS Средний

Описание

Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers improper handling of a deleted window object.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
chromium-browsernot-affectedpackage
webkitnot-affectedpackage

Примечания

  • poc seems to cause a dos in both chromium and webkit; not sure if code execution is possible

  • This is Safari only

EPSS

Процентиль: 98%
0.64858
Средний

Связанные уязвимости

nvd
больше 15 лет назад

Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers improper handling of a deleted window object.

github
больше 3 лет назад

Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers improper handling of a deleted window object.

EPSS

Процентиль: 98%
0.64858
Средний