CVE-2010-1785: Buffer Overflow
WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; accesses uninitialized memory during processing of the (1) :first-letter and (2) :first-line pseudo-elements in an SVG text element, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1785?
CVE-2010-1785 is considered a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2010-1785?
To fix CVE-2010-1785, users should update to the latest version of Apple Safari or WebKit that addresses this vulnerability.
What systems are affected by CVE-2010-1785?
CVE-2010-1785 affects Apple Safari versions prior to 5.0.1 and certain versions of WebKitGTK.
Can CVE-2010-1785 allow an attacker to access sensitive information?
Yes, CVE-2010-1785 may allow attackers to access sensitive information due to uninitialized memory access.
Is there a known exploit for CVE-2010-1785?
Yes, there are known exploits for CVE-2010-1785 that take advantage of the vulnerability in web browsers.