CVE-2010-1394: XSS
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML document fragments.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1394?
CVE-2010-1394 is classified as a moderate severity cross-site scripting security vulnerability.
How do I fix CVE-2010-1394?
To mitigate the effects of CVE-2010-1394, you should update Apple Safari to version 5.0 or later.
What are the affected versions for CVE-2010-1394?
CVE-2010-1394 affects Apple Safari versions prior to 5.0 and WebKit versions before the necessary patches.
Can CVE-2010-1394 affect my web applications?
Yes, CVE-2010-1394 can allow attackers to inject arbitrary web scripts into vulnerable web applications on affected browsers.
What platforms are vulnerable to CVE-2010-1394?
CVE-2010-1394 affects Mac OS X 10.4 to 10.6 and is applicable to certain versions of Apple Safari on those operating systems.