CVE-2010-1387: Use After Free
Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1387?
CVE-2010-1387 has a high severity rating due to its potential to allow remote attackers to execute arbitrary code or cause application crashes.
How do I fix CVE-2010-1387?
To mitigate CVE-2010-1387, update Apple iTunes to version 9.2 or later on Windows, and ensure iOS is updated to at least version 4 on iPhone and iPod touch devices.
What versions are affected by CVE-2010-1387?
CVE-2010-1387 affects Apple iTunes versions prior to 9.2 and iOS versions before 4 on iPhone and iPod touch.
Can CVE-2010-1387 cause denial of service?
Yes, CVE-2010-1387 can cause denial of service by crashing the application when exploited.
What is the nature of CVE-2010-1387 vulnerability?
CVE-2010-1387 is a use-after-free vulnerability in the JavaScriptCore component of WebKit, which can be exploited during page transitions.