CVE-2010-1383
UnknownEPSS 2.08%
Last modified
CVE-2010-1383 is a vulnerability of currently unknown severity. CFNetwork in Apple Safari before 5.0.6 on Windows allows remote web servers to execute arbitrary code by replaying the NTLM credentials of a client user, related to a "credential reflection" issue.. EPSS estimates a 2.08% chance of exploitation in the next 30 days.
Description
CFNetwork in Apple Safari before 5.0.6 on Windows allows remote web servers to execute arbitrary code by replaying the NTLM credentials of a client user, related to a "credential reflection" issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Cfnetwork | All versions |
| Apple | Safari | <= 5.0.5 |
| Apple | Safari | 1.0 |
| Apple | Safari | 1.0.0 |
| Apple | Safari | 1.0.0b1 |
| Apple | Safari | 1.0.0b2 |
| Apple | Safari | 1.0.1 |
| Apple | Safari | 1.0.2 |
| Apple | Safari | 1.0.3 |
| Apple | Safari | 1.1 |
| Apple | Safari | 1.1.0 |
| Apple | Safari | 1.1.1 |
| Apple | Safari | 1.2 |
| Apple | Safari | 1.2.0 |
| Apple | Safari | 1.2.1 |
| Apple | Safari | 1.2.2 |
| Apple | Safari | 1.2.3 |
| Apple | Safari | 1.2.4 |
| Apple | Safari | 1.2.5 |
| Apple | Safari | 1.3 |
| Apple | Safari | 1.3.0 |
| Apple | Safari | 1.3.1 |
| Apple | Safari | 1.3.2 |
| Apple | Safari | 2 |
| Apple | Safari | 2.0 |
| Apple | Safari | 2.0.0 |
| Apple | Safari | 2.0.1 |
| Apple | Safari | 2.0.2 |
| Apple | Safari | 2.0.3 |
| Apple | Safari | 2.0.4 |
| Apple | Safari | 3 |
| Apple | Safari | 3.0 |
| Apple | Safari | 3.0.0 |
| Apple | Safari | 3.0.0b |
| Apple | Safari | 3.0.1 |
| Apple | Safari | 3.0.1b |
| Apple | Safari | 3.0.2 |
| Apple | Safari | 3.0.2b |
| Apple | Safari | 3.0.3 |
| Apple | Safari | 3.0.3b |
| Apple | Safari | 3.0.4 |
| Apple | Safari | 3.0.4b |
| Apple | Safari | 3.1.0 |
| Apple | Safari | 3.1.0b |
| Apple | Safari | 3.1.1 |
| Apple | Safari | 3.1.2 |
| Apple | Safari | 3.2.0 |
| Apple | Safari | 3.2.1 |
| Apple | Safari | 3.2.2 |
| Apple | Safari | 4.1 |
Showing 50 of 57 affected configurations. See NVD for the full list.
References
- http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.htmlPatch, Vendor Advisory
- http://support.apple.com/kb/HT4808Vendor Advisory
- http://lists.apple.com/archives/security-announce/2011//Jul/msg00002.htmlPatch, Vendor Advisory
- http://support.apple.com/kb/HT4808Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-1383?
CFNetwork in Apple Safari before 5.0.6 on Windows allows remote web servers to execute arbitrary code by replaying the NTLM credentials of a client user, related to a "credential reflection" issue.
How severe is CVE-2010-1383?
Severity scoring for CVE-2010-1383 is pending analysis. The EPSS model estimates a 2.08% probability of exploitation in the next 30 days.
How do I fix CVE-2010-1383?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-1377Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates …
- CVE-2010-1378OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not prop…9.8
- CVE-2010-1379Printer Setup in Apple Mac OS X 10.6 before 10.6.4 does not …
- CVE-2010-1380Integer overflow in the cgtexttops CUPS filter in Printing i…
- CVE-2010-1381The default configuration of SMB File Server in Apple Mac OS…
- CVE-2010-1382Cross-site scripting (XSS) vulnerability in Wiki Server in A…
- CVE-2010-1384Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Wi…
- CVE-2010-1385Use-after-free vulnerability in Apple Safari before 5.0 on M…
- CVE-2010-1386page/Geolocation.cpp in WebCore in WebKit before r56188 and …
- CVE-2010-1387Use-after-free vulnerability in JavaScriptCore in WebKit in …
- CVE-2010-1388WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 1…
- CVE-2010-1389Cross-site scripting (XSS) vulnerability in WebKit in Apple …
Are you affected by CVE-2010-1383?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
