Vulnerability Description
cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.3 and 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in the BACKGROUND attribute of a BODY element.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | 4.0.3 |
| Microsoft | Windows | All versions |
References
- http://nobytes.com/exploits/Safari_4.0.4_background_DoS_pl.txtExploit
- http://www.securityfocus.com/bid/38447Exploit
- http://nobytes.com/exploits/Safari_4.0.4_background_DoS_pl.txtExploit
- http://www.securityfocus.com/bid/38447Exploit
FAQ
What is CVE-2010-0924?
CVE-2010-0924 is a vulnerability with a CVSS score of 5.0 (MEDIUM). cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.3 and 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long st...
How severe is CVE-2010-0924?
CVE-2010-0924 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-0924?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Safari, Microsoft Windows.