CVE-2010-1939

Apple Safari - Resource Management Error

Title source: rule

Description

Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers improper handling of a deleted window object.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Alexey Sintsov · textremotewindows
https://www.exploit-db.com/exploits/12614
exploitdb WORKING POC VERIFIED
by Krystian Kloskowski · htmlremotewindows
https://www.exploit-db.com/exploits/12573

Scores

EPSS 0.6486
EPSS Percentile 98.5%

Details

CWE
CWE-399
Status published
Products (1)
apple/safari 4.0.5
Published May 13, 2010
Tracked Since Feb 18, 2026