CVE-2010-1822

Severity CVSS v4.0:
Pending analysis
Type:
CWE-704 Incorrect Type Conversion or Cast
Publication date:
04/10/2010
Last modified:
11/04/2025

Description

WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3 and Google Chrome before 6.0.472.62, does not properly perform a cast of an unspecified variable, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG element in a non-SVG document.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* 4.1.3 (excluding)
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* 5.0 (including) 5.0.3 (excluding)
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* 6.0.472.62 (excluding)
cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools