CVE-2010-3257
Last modified
CVE-2010-3257 is a vulnerability of currently unknown severity. Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element focus.. EPSS estimates a 3.31% chance of exploitation in the next 30 days.
Description
Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element focus.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chrome | < 6.0.472.53 | |
| Webkitgtk | Webkitgtk | < 1.2.6 |
| Apple | Safari | < 4.1.3 |
| Apple | Safari | >= 5.0, < 5.0.3 |
| Apple | Iphone Os | < 4.2 |
| Canonical | Ubuntu Linux | 9.10 |
| Canonical | Ubuntu Linux | 10.04 |
| Canonical | Ubuntu Linux | 10.10 |
References
- http://code.google.com/p/chromium/issues/detail?id=52443Vendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/41856Third Party Advisory
- http://secunia.com/advisories/42314Third Party Advisory
- http://secunia.com/advisories/43068Third Party Advisory
- http://secunia.com/advisories/43086Third Party Advisory
- http://support.apple.com/kb/HT4455Third Party Advisory
- http://support.apple.com/kb/HT4456Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:039Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0177.htmlThird Party Advisory
- http://www.securityfocus.com/bid/44204Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1006-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2722Third Party Advisory
- http://www.vupen.com/english/advisories/2010/3046Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0212Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0216Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0552Third Party Advisory
- http://code.google.com/p/chromium/issues/detail?id=52443Vendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/41856Third Party Advisory
- http://secunia.com/advisories/42314Third Party Advisory
- http://secunia.com/advisories/43068Third Party Advisory
- http://secunia.com/advisories/43086Third Party Advisory
- http://support.apple.com/kb/HT4455Third Party Advisory
- http://support.apple.com/kb/HT4456Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:039Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0177.htmlThird Party Advisory
- http://www.securityfocus.com/bid/44204Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1006-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/2722Third Party Advisory
- http://www.vupen.com/english/advisories/2010/3046Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0212Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0216Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0552Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-3257?
How severe is CVE-2010-3257?
How do I fix CVE-2010-3257?
Are you affected by CVE-2010-3257?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
