CVE-2010-1822 describes a critical vulnerability in WebKit, affecting Apple Safari and Google Chrome versions prior to their respective patches. This flaw, categorized as a type confusion (CWE-704), allows remote attackers to execute arbitrary code or cause a denial of service by embedding a specially crafted SVG element within a non-SVG document. With a CVSS score of 8.8 (HIGH), it presents a significant risk due to its network-based attack vector and low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence like Metasploit or ExploitDB entries exist, and there's minimal community discussion or media coverage, the vulnerability's age suggests it is unlikely to be actively exploited in the wild today.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.3CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
>= 5.0, < 5.0.3CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 6.0.472.62CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
11.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:* | ||
11.3CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.