CVE-2010-1415 describes a critical vulnerability in WebKit, specifically affecting Apple Safari versions prior to 5.0 on Mac OS X and Windows, and prior to 4.1 on Mac OS X 10.4. This flaw, an "API abuse issue" related to libxml contexts, allows remote attackers to execute arbitrary code or trigger a denial of service through a specially crafted HTML document. With a CVSS score of 9.3 (Critical) and a FAUCET Risk Score of 96/100, this vulnerability presents a significant risk due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. While no active exploitation, Metasploit modules, or ExploitDB entries are reported, and community discussion and media coverage are minimal, the high EPSS score indicates a notable potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.0.5CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:4.0:*:*:*:*:*:*:* | ||
4.0.0bCPE matchmatch criteria | cpe:2.3:a:apple:safari:4.0.0b:*:*:*:*:*:*:* | ||
4.0.1CPE matchmatch criteria | cpe:2.3:a:apple:safari:4.0.1:*:*:*:*:*:*:* | ||
4.0.2CPE matchmatch criteria | cpe:2.3:a:apple:safari:4.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.