CVE-2010-1822
HIGHSafari < 4.1.3 and 5.0.x < 5.0.3 - Remote Code Execution via SVG Element Type Confusion
Title source: llmDescription
WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3 and Google Chrome before 6.0.472.62, does not properly perform a cast of an unspecified variable, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG element in a non-SVG document.
References (13)
Core 13
Core References
Permissions Required, Vendor Advisory x_refsource_confirm
https://bugs.webkit.org/show_bug.cgi?id=45562
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43068
Exploit, Issue Tracking, Mailing List, Vendor Advisory x_refsource_confirm
http://code.google.com/p/chromium/issues/detail?id=55114
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4455
Broken Link, Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0212
Broken Link, Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/3046
Mailing List, Third Party Advisory vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
Mailing List, Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.html
Broken Link third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/42314
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4456
Release Notes, Vendor Advisory x_refsource_confirm
http://googlechromereleases.blogspot.com/2010/09/stable-beta-channel-updates_17.html
Mailing List, Third Party Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html
Third Party Advisory vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6691
Scores
CVSS v3
8.8
EPSS
0.0218
EPSS Percentile
79.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-704
Status
published
Products (4)
apple/safari
< 4.1.3
google/chrome
< 6.0.472.62
opensuse/opensuse
11.2
opensuse/opensuse
11.3
Published
Oct 04, 2010
Tracked Since
Feb 18, 2026