CVE-2010-1119

Apple Safari <5.0 - Use After Free

Title source: llm

Description

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo and Ralf Philipp Weinmann during a Pwn2Own competition at CanSecWest 2010.

Exploits (1)

exploitdb WORKING POC VERIFIED
by MJ Keith · htmlremoteandroid
https://www.exploit-db.com/exploits/16974

Scores

EPSS 0.4578
EPSS Percentile 97.6%

Details

CWE
CWE-399
Status published
Products (46)
apple/iphone_os 2.0
apple/iphone_os 2.0.0
apple/iphone_os 2.0.1
apple/iphone_os 2.0.2
apple/iphone_os 2.1
apple/iphone_os 2.1.1
apple/iphone_os 2.2
apple/iphone_os 2.2.1
apple/iphone_os 3.0
apple/iphone_os 3.0.1
... and 36 more
Published Mar 25, 2010
Tracked Since Feb 18, 2026