Vulnerability Description
cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in the SRC attribute of a (1) IMG or (2) IFRAME element.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | 4.0.4 |
| Microsoft | Windows | All versions |
References
- http://nobytes.com/exploits/Safari_4.0.4_background_DoS_pl.txtExploit
- http://nobytes.com/exploits/Safari_4.0.4_background_DoS_pl.txtExploit
FAQ
What is CVE-2010-0925?
CVE-2010-0925 is a vulnerability with a CVSS score of 5.0 (MEDIUM). cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in th...
How severe is CVE-2010-0925?
CVE-2010-0925 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-0925?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Safari, Microsoft Windows.