First published: Thu May 13 2010(Updated: )
Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers improper handling of a deleted window object.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | =4.0.5 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1939 has been classified as a critical vulnerability allowing remote code execution.
To fix CVE-2010-1939, upgrade Apple Safari to the latest version available.
CVE-2010-1939 specifically affects Apple Safari version 4.0.5 on Windows.
Yes, CVE-2010-1939 can potentially be exploited by tricking users into opening a malicious HTML document.
Exploiting CVE-2010-1939 can lead to arbitrary code execution, giving attackers full control over affected systems.