CVE-2010-0049
Apple Safari < 4.0.5 - Use-After-Free via RTL Text Directionality
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-0049. PoCs published by wushi.
AI-analyzed exploit summary This exploit targets a memory corruption vulnerability in WebKit (CVE-2010-0049) by using heap spraying and a malformed HTML structure to achieve arbitrary code execution. The shellcode is embedded in the JavaScript, and the exploit manipulates DOM elements to trigger the vulnerability.
Description
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via HTML elements with right-to-left (RTL) text directionality.
Exploits (1)
This exploit targets a memory corruption vulnerability in WebKit (CVE-2010-0049) by using heap spraying and a malformed HTML structure to achieve arbitrary code execution. The shellcode is embedded in the JavaScript, and the exploit manipulates DOM elements to trigger the vulnerability.