CVE-2010-1790: Critical severity safari vulnerability
WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; does not properly handle just-in-time (JIT) compiled JavaScript stubs, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to a "reentrancy issue."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1790?
CVE-2010-1790 has a high severity rating as it allows remote code execution or denial of service.
How do I fix CVE-2010-1790?
To fix CVE-2010-1790, update to Apple Safari version 5.0.1 or later.
Which software versions are affected by CVE-2010-1790?
CVE-2010-1790 affects Apple Safari versions before 5.0.1 and WebKitGTK versions before 1.2.6.
What types of attacks can exploit CVE-2010-1790?
CVE-2010-1790 can be exploited to execute arbitrary code or cause a denial of service.
Is there a workaround for CVE-2010-1790?
Disabling JavaScript in Safari can act as a temporary workaround for CVE-2010-1790.