Vulnerabilities > CVE-2010-1179 - Numeric Errors vulnerability in Apple Safari

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
apple
CWE-189
critical
exploit available

Summary

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large integer in the numcolors attribute of a recolorinfo element in a VML file, possibly a related issue to CVE-2007-0024.

Vulnerable Configurations

Part Description Count
Application
Apple
1
OS
Apple
2

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionBad "VML" Remote DoS on Safari for iPhone & iPod Touch. CVE-2010-1179. Dos exploit for ios platform
fileexploits/ios/dos/11890.txt
idEDB-ID:11890
last seen2016-02-01
modified2010-03-26
platformios
port
published2010-03-26
reporterNishant Das Patnaik
sourcehttps://www.exploit-db.com/download/11890/
titleiOS Safari - Bad "VML" Remote DoS
typedos