CVE-2010-1029 is a stack consumption vulnerability in the WebCore::CSSSelector function of WebKit, impacting Apple Safari 4.0.4, iPhone OS, and Google Chrome 4.0.249. This flaw allows remote attackers to trigger a denial of service (application crash) or potentially execute arbitrary code through a specially crafted STYLE element containing numerous “*>” sequences. Rated with a CVSS score of 5.0, it is a low-complexity attack requiring no authentication, with a primary impact of availability. While not listed in CISA's KEV catalog, proof-of-concept exploit code is publicly available on ExploitDB, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.4CPE matchmatch criteria | cpe:2.3:a:apple:safari:4.0.4:*:*:*:*:*:*:* | ||
4.0.249.0CPE matchmatch criteria | cpe:2.3:a:google:chrome:4.0.249.0:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.