CVE-2010-1177: Code Injection
Published Mar 29, 2010
·Updated
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings.
Affected Software
6 affected components
Safari
iPhone OS=3.1.3
iPhone OS=3.1.3
All of the following
Safari
Any of the following
iPhone OS=3.1.3
iPhone OS=3.1.3
Event History
Mar 29, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
07:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·07:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1177?
CVE-2010-1177 is classified as a denial of service vulnerability that may lead to application crashes.
2
How do I fix CVE-2010-1177?
To mitigate CVE-2010-1177, users should update their Safari version to the latest available release from Apple.
3
What systems are affected by CVE-2010-1177?
CVE-2010-1177 affects Safari on iPhone OS 3.1.3 specifically for iPod touch and iPhone devices.
4
Can CVE-2010-1177 allow remote code execution?
Yes, CVE-2010-1177 may potentially allow remote attackers to execute arbitrary code under certain conditions.
5
When was CVE-2010-1177 reported?
CVE-2010-1177 was reported in 2010 and is associated with vulnerabilities in older versions of Safari.