CVE
- Id
- 43703
- CVE No.
- CVE-2010-1119
- Status
- Candidate
- Description
- Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo and Ralf Philipp Weinmann during a Pwn2Own competition at CanSecWest 2010.
- Phase
- Assigned (20100325)
- Votes
- None (candidate not yet proposed)
- Comments