Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-1807

74
FAUCET Score

CVE-2010-1807 describes a critical vulnerability in WebKit, affecting Apple Safari 4.x/5.x, Android before 2.2, and webkitgtk before 1.2.6. The flaw stems from improper validation of floating-point data, specifically related to non-standard NaN representation. This allows remote attackers to execute arbitrary code or cause a denial of service via a crafted HTML document. With a CVSS score of 9.3 (Critical) and a FAUCET Risk Score of 99/100, this vulnerability poses a significant risk due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, exploit code is publicly available on ExploitDB, demonstrating remote code execution and use-after-free attacks against Google Android 2.0/2.1. Despite the existence of public exploits, there is no evidence of active exploitation, and community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
4.0CPE matchmatch criteria
cpe:2.3:a:apple:safari:4.0:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:a:apple:safari:4.0:beta:*:*:*:*:*:*
4.0.0bCPE matchmatch criteria
cpe:2.3:a:apple:safari:4.0.0b:*:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:apple:safari:4.0.1:*:*:*:*:*:*:*
4.0.2CPE matchmatch criteria
cpe:2.3:a:apple:safari:4.0.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
61.32%
Probability of exploitation in next 30 days
EPSS Percentile
99.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-15548 · Nov 15, 2010
This CVE's current EPSS score of 0.6132 is in the 99th percentile among its peer group of 8,914 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: webkitgtk-0:1.2.6-2.el6_0
View patch
applevendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2010-1807Moderate

webkit: input validation error when parsing certain NaN values

Sep 7, 2010

References

lists.apple.com / archives/security-announce/2010//Nov/msg00003.html
lists.apple.com / archives/security-announce/2010//Sep/msg00001.html
Vendor Advisory
lists.opensuse.org / opensuse-security-announce/2011-01/msg00006.html
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/41856
Vendor Advisory
secunia.com / advisories/42314
secunia.com / advisories/43068
Vendor Advisory
secunia.com / advisories/43086
Vendor Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11964
support.apple.com / kb/HT4333
Vendor Advisory
support.apple.com / kb/HT4456
trac.webkit.org / changeset/64706
computerworld.com / s/article/9195058/Researcher_to_release_Web_based_Android_attack
mandriva.com / security/advisories
redhat.com / support/errata/RHSA-2011-0177.html
securityfocus.com / bid/43047
Patch
ubuntu.com / usn/USN-1006-1
vupen.com / english/advisories/2010/2722
Vendor Advisory
vupen.com / english/advisories/2010/3046
Vendor Advisory
vupen.com / english/advisories/2011/0212
Vendor Advisory
vupen.com / english/advisories/2011/0216
Vendor Advisory
vupen.com / english/advisories/2011/0552
Vendor Advisory