CVE-2010-1778

Apple Safari < 5.0 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via an RSS feed.

Scores

EPSS 0.0020
EPSS Percentile 41.7%

Classification

CWE
CWE-79
Status published

Affected Products (10)

apple/safari < 5.0
apple/safari
apple/safari
apple/safari
apple/safari
apple/safari
apple/safari
apple/safari
apple/webkit
n/a/n/a

Timeline

Published Jul 30, 2010
Tracked Since Feb 18, 2026