CVE-2010-1226: Input Validation
The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of service (Safari, Mail, or Springboard crash) via a crafted innerHTML property of a DIV element, related to a "malformed character" issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1226?
CVE-2010-1226 has been classified as a medium severity vulnerability impacting the Apple iPhone OS.
How do I fix CVE-2010-1226?
To address CVE-2010-1226, users should update their devices to the latest version of Apple iPhone OS that is available.
Which versions of Apple iPhone are affected by CVE-2010-1226?
CVE-2010-1226 affects Apple iPhone OS version 3.1 and version 3.1.3 on the iPhone 3GS.
What type of attack is associated with CVE-2010-1226?
CVE-2010-1226 is associated with a denial of service attack that can crash the Safari, Mail, or Springboard applications.
Can CVE-2010-1226 be exploited remotely?
Yes, CVE-2010-1226 can be exploited remotely by delivering a crafted innerHTML property to vulnerable applications.