CVE-2010-1823

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
24/09/2010
Last modified:
11/04/2025

Description

Use-after-free vulnerability in WebKit before r65958, as used in Google Chrome before 6.0.472.59, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger use of document APIs such as document.close during parsing, as demonstrated by a Cascading Style Sheets (CSS) file referencing an invalid SVG font, aka rdar problem 8442098.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* 6.0.472.59 (excluding)
cpe:2.3:a:apple:itunes:*:*:*:*:*:*:*:* 10.5 (excluding)
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* 5.0.6 (excluding)