CVE-2010-1807

WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to non-standard NaN representation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
appleCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
applesafari
4.0
applesafari
4.0:beta
applesafari
4.0.0b:b
applesafari
4.0.1
applesafari
4.0.2
applesafari
4.0.3
applesafari
4.0.4
applesafari
4.0.5
applesafari
4.1
applesafari
4.1.1
applesafari
5.0
applesafari
5.0.1
googleandroid
𝑥
≤ 2.1
googleandroid
1.0
googleandroid
1.1
googleandroid
1.5
googleandroid
1.6
googleandroid
2.0
webkitgtkwebkitgtk
𝑥
≤ 1.2.5
webkitgtkwebkitgtk
1.2.0
webkitgtkwebkitgtk
1.2.1
webkitgtkwebkitgtk
1.2.2
webkitgtkwebkitgtk
1.2.3
webkitgtkwebkitgtk
1.2.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qt4-x11
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
ignored
karmic
ignored
jaunty
ignored
hardy
not-affected
dapper
not-affected
webkit
oneiric
not-affected
natty
not-affected
maverick
Fixed 1.2.5-0ubuntu0.10.10.1
released
lucid
Fixed 1.2.5-0ubuntu0.10.04.1
released
karmic
Fixed 1.2.5-0ubuntu0.9.10.1
released
jaunty
ignored
hardy
ignored
dapper
dne
References