Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-1770

29
FAUCET Score

CVE-2010-1770 describes a memory corruption vulnerability in WebKit, affecting Apple Safari and Google Chrome, stemming from improper handling of text node transformations with the IBM1147 character set. This flaw allows remote attackers to execute arbitrary code or cause a denial of service via a crafted HTML document. With a CVSS score of 9.3, this vulnerability is considered critical due to its network-based attack vector, medium complexity, and complete impact on confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 4.0.5CPE matchmatch criteria
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:apple:webkit:*:*:*:*:*:*:*:*
< 5.0.375.70CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
9.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*
10.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.76%
Probability of exploitation in next 30 days
EPSS Percentile
91.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0476 is in the 57th percentile among its peer group of 8,920 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (3)

applevendor investigatingvia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: qt
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: webkitgtk

Vendor Advisories (1)

redhatCVE-2010-1770Critical

WebKit: type checking vulnerability in handling of text nodes (ZDI-CAN-765)

Jun 7, 2010

References

code.google.com / p/chromium/issues/detail
Vendor Advisory
googlechromereleases.blogspot.com / 2010/06/stable-channel-update.html
Vendor Advisory
lists.apple.com / archives/security-announce/2010/Jun/msg00000.html
Mailing ListPatchVendor Advisory
lists.apple.com / archives/security-announce/2010//Jun/msg00002.html
Mailing ListVendor Advisory
lists.apple.com / archives/security-announce/2010//Nov/msg00003.html
Mailing ListVendor Advisory
lists.apple.com / archives/security-announce/2010//Sep/msg00002.html
Mailing ListVendor Advisory
lists.opensuse.org / opensuse-security-announce/2011-01/msg00006.html
Mailing ListThird Party Advisory
secunia.com / advisories/40072
Third Party Advisory
secunia.com / advisories/40105
Third Party Advisory
secunia.com / advisories/40196
Third Party Advisory
secunia.com / advisories/41856
Third Party Advisory
secunia.com / advisories/42314
Third Party Advisory
secunia.com / advisories/43068
Third Party Advisory
securitytracker.com / id
Third Party AdvisoryVDB Entry
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7099
Third Party Advisory
support.apple.com / kb/HT4196
Vendor Advisory
support.apple.com / kb/HT4220
Vendor Advisory
support.apple.com / kb/HT4334
Vendor Advisory
support.apple.com / kb/HT4456
Vendor Advisory
mandriva.com / security/advisories
Third Party Advisory
securityfocus.com / bid/40620
PatchThird Party AdvisoryVDB Entry
ubuntu.com / usn/USN-1006-1
Third Party Advisory
vupen.com / english/advisories/2010/1373
Permissions RequiredThird Party Advisory
vupen.com / english/advisories/2010/1512
Permissions RequiredThird Party Advisory
vupen.com / english/advisories/2010/2722
Permissions RequiredThird Party Advisory
vupen.com / english/advisories/2011/0212
Permissions RequiredThird Party Advisory
vupen.com / english/advisories/2011/0552
Permissions RequiredThird Party Advisory
zerodayinitiative.com / advisories/ZDI-10-093
Third Party AdvisoryVDB Entry