CVE-2010-1770

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document containing a BR element, related to a "type checking issue."
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
appleCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
applesafari
𝑥
≤ 4.0.5
applewebkit
*
applesafari
𝑥
≤ 4.0.5
applewebkit
*
googlechrome
𝑥
< 5.0.375.70
canonicalubuntu_linux
9.10
canonicalubuntu_linux
10.04
canonicalubuntu_linux
10.04.4
canonicalubuntu_linux
10.10
opensuseopensuse
11.2
opensuseopensuse
11.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
oneiric
ignored
natty
ignored
maverick
ignored
lucid
ignored
karmic
dne
jaunty
dne
hardy
dne
dapper
dne
qt4-x11
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
ignored
karmic
ignored
jaunty
ignored
hardy
not-affected
dapper
not-affected
webkit
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
Fixed 1.2.5-0ubuntu0.10.04.1
released
karmic
Fixed 1.2.5-0ubuntu0.9.10.1
released
jaunty
ignored
hardy
ignored
dapper
dne
References