what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 1 of 1 RSS Feed

Files

Zero Day Initiative Advisory 10-100
Posted Jun 9, 2010
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 10-100 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple's Webkit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within how the application duplicates event listeners in .svg documents. Upon creating an AnimateTransform object, the library will create a timer to handle the transformation and duplicate the object's event listener into Webkit's "shadow tree" of the image. Upon destruction of the shadow tree and the original tree, the application will destroy the Element containing the event listener twice. This can lead to code execution under the context of the application.

tags | advisory, remote, arbitrary, code execution
systems | apple
advisories | CVE-2010-1402
SHA-256 | 7d0809e72c60007e344db72c24187f922e778eaf606c4c95a6c3a5200e7911aa
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
China Is Digging A Big Frickin' Hole 33,000 Feet Into The Earth
Posted Jun 2, 2023

tags | headline, government, china, science
Researchers Tell Owners To Assume Compromise Of Unpatched Zyxel Firewalls
Posted Jun 1, 2023

tags | headline, hacker, flaw, backdoor
War Crimes Evidence Erased By Social Media Firms
Posted Jun 1, 2023

tags | headline, government, data loss, cyberwar, social, military
New Vulnerability Gives MacOS Users A Migraine
Posted Jun 1, 2023

tags | headline, flaw, apple
Amazon To Pay $30.8M For Alexa And Ring Privacy Violations
Posted Jun 1, 2023

tags | headline, government, privacy, usa, amazon, data loss
Russia Says U.S. Accessed Thousands Of Apple Phones In Spy Plot
Posted Jun 1, 2023

tags | headline, government, usa, phone, russia, cyberwar, spyware, apple
Organizations Warned Of Backdoor In Hundreds Of Gigabyte Motherboards
Posted May 31, 2023

tags | headline, hacker, microsoft, flaw, backdoor
XFS Bug In Linux Kernel 6.3.3 Coincides With SGI Code Comebank
Posted May 31, 2023

tags | headline, linux, flaw
Cyberwar Manufacturers Plot To Stay On Right Side Of US
Posted May 31, 2023

tags | headline, government, malware, usa, cyberwar, spyware
Critical Barracuda 0-Day Was Used To Backdoor Networks For 8 Months
Posted May 31, 2023

tags | headline, hacker, data loss, flaw, backdoor
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close