CVE-2010-1781
Last modified
CVE-2010-1781 is a vulnerability of currently unknown severity. Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rendering of an inline element.. EPSS estimates a 4.30% chance of exploitation in the next 30 days.
Description
Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rendering of an inline element.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apple | Iphone Os | < 4.1 |
| Canonical | Ubuntu Linux | 9.10 |
| Canonical | Ubuntu Linux | 10.04 |
| Canonical | Ubuntu Linux | 10.10 |
References
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlMailing List, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.htmlMailing List, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/41856Third Party Advisory
- http://secunia.com/advisories/42314Third Party Advisory
- http://secunia.com/advisories/43068Third Party Advisory
- http://support.apple.com/kb/HT4334Vendor Advisory
- http://support.apple.com/kb/HT4456Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:039Third Party Advisory
- http://www.securityfocus.com/bid/43077Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1006-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2722Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0212Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0552Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61698Third Party Advisory, VDB Entry
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlMailing List, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.htmlMailing List, Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/41856Third Party Advisory
- http://secunia.com/advisories/42314Third Party Advisory
- http://secunia.com/advisories/43068Third Party Advisory
- http://support.apple.com/kb/HT4334Vendor Advisory
- http://support.apple.com/kb/HT4456Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:039Third Party Advisory
- http://www.securityfocus.com/bid/43077Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1006-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2722Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0212Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0552Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61698Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-1781?
How severe is CVE-2010-1781?
How do I fix CVE-2010-1781?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-1775Race condition in Passcode Lock in Apple iOS before 4 on the…
- CVE-2010-1776Find My iPhone on iOS 2.0 through 3.1.3 for iPhone 3G and la…
- CVE-2010-1777Buffer overflow in Apple iTunes before 9.2.1 allows remote a…
- CVE-2010-1778Cross-site scripting (XSS) vulnerability in Apple Safari bef…
- CVE-2010-1779Rejected reason: This candidate is unused by its CNA.
- CVE-2010-1780Use-after-free vulnerability in WebKit in Apple Safari befor…
- CVE-2010-1782WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through…
- CVE-2010-1783WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through…
- CVE-2010-1784The counters functionality in the Cascading Style Sheets (CS…
- CVE-2010-1785WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through…
- CVE-2010-1786Use-after-free vulnerability in WebKit in Apple Safari befor…
- CVE-2010-1787WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through…
Are you affected by CVE-2010-1781?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
