CVE-2010-0050 is a use-after-free vulnerability in WebKit, affecting Apple Safari before version 4.0.5, as well as products from Canonical, Fedora Project, and OpenSUSE. This high-severity vulnerability (CVSS 8.8) allows remote attackers to execute arbitrary code or cause a denial of service through specially crafted HTML with improperly nested tags, requiring user interaction. While there is no evidence of active exploitation, a denial-of-service exploit (EDB-12425) exists, but there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.5CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
>= 2.0, < 4.0CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:12:*:*:*:*:*:*:* | ||
13CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.