Record summary

CVE-2010-1119 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.

Description

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo and Ralf Philipp Weinmann during a Pwn2Own competition at CanSecWest 2010.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBGoogle Android 2.0/2.1/2.1.1 - WebKit Use-After-FreeExploitDB exploitby MJ KeithNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 18