CVE-2010-3257
Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element focus.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 3.31% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- google/chrome · webkitgtk/webkitgtk · apple/safari · apple/iphone os · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://code.google.com/p/chromium/issues/detail?id=52443Vendor Advisory
- http://googlechromereleases.blogspot.com/2010/09/stable-and-beta-channel-updates.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/41856Third Party Advisory
- http://secunia.com/advisories/42314Third Party Advisory
- http://secunia.com/advisories/43068Third Party Advisory
- http://secunia.com/advisories/43086Third Party Advisory
- http://support.apple.com/kb/HT4455Third Party Advisory
- http://support.apple.com/kb/HT4456Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:039Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0177.htmlThird Party Advisory
- http://www.securityfocus.com/bid/44204Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1006-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2722Third Party Advisory
- http://www.vupen.com/english/advisories/2010/3046Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0212Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0216Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0552Third Party Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12138Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=52443Vendor Advisory
- http://googlechromereleases.blogspot.com/2010/09/stable-and-beta-channel-updates.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/41856Third Party Advisory
- http://secunia.com/advisories/42314Third Party Advisory
- http://secunia.com/advisories/43068Third Party Advisory
- http://secunia.com/advisories/43086Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.