CVE-2010-1119
Apple Safari <5.0 - Use After Free
Title source: llmDescription
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo and Ralf Philipp Weinmann during a Pwn2Own competition at CanSecWest 2010.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by MJ Keith · htmlremoteandroid
https://www.exploit-db.com/exploits/16974
References (17)
Scores
EPSS
0.4578
EPSS Percentile
97.6%
Details
CWE
CWE-399
Status
published
Products (46)
apple/iphone_os
2.0
apple/iphone_os
2.0.0
apple/iphone_os
2.0.1
apple/iphone_os
2.0.2
apple/iphone_os
2.1
apple/iphone_os
2.1.1
apple/iphone_os
2.2
apple/iphone_os
2.2.1
apple/iphone_os
3.0
apple/iphone_os
3.0.1
... and 36 more
Published
Mar 25, 2010
Tracked Since
Feb 18, 2026