Sploitus

CVE-2010-1029

2 known exploits for CVE-2010-1029

Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a STYLE element composed of a large number of *> sequences.

Affected products
Google Chrome, Safari, Webkit
Apple Safari
= 4.0.4
Fix
Available
CVSS 2.0
5.0 MEDIUM
EPSS
10.4% (95th percentile)
Weakness
CWE-399
NVD status
Modified
Published
2010-03-19
CVE-2010-1029 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2010-1029

Proof-of-concept code and exploit modules indexed by Sploitus