Vulnerability Name: | CVE-2010-1176 (CCN-57215) | ||||||||
Assigned: | 2010-03-26 | ||||||||
Published: | 2010-03-26 | ||||||||
Updated: | 2010-03-30 | ||||||||
Summary: | Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to an array of long strings, an array of IMG elements with crafted strings in their SRC attributes, a TBODY element with no associated TABLE element, and certain calls to the delete operator and the cloneNode, clearAttributes, and CollectGarbage methods, possibly a related issue to CVE-2009-0075. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 8.4 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:U/RC:C)
6.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:POC/RL:U/RC:C)
| ||||||||
Vulnerability Type: | CWE-94 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-1176 Source: MISC Type: Exploit http://nishantdaspatnaik.yolasite.com/ipodpoc1.php Source: CCN Type: Apple Web site iPhone Source: EXPLOIT-DB Type: Exploit 11891 Source: BID Type: Exploit 38989 Source: CCN Type: BID-38989 Apple iPhone/iPod Touch Safari Malformed Image Remote Code Execution Vulnerability Source: XF Type: UNKNOWN safari-iphone-ipod-code-execution(57215) Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [03-26-2010] | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |