CVE
- Id
- 43971
- CVE No.
- CVE-2010-1387
- Status
- Candidate
- Description
- Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.
- Phase
- Assigned (20100415)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
478954 | 43971 | CVE-2010-1387 | CONFIRM:http://support.apple.com/kb/HT4220 | View |
478955 | 43971 | CVE-2010-1387 | CONFIRM:http://support.apple.com/kb/HT4225 | View |
478956 | 43971 | CVE-2010-1387 | CONFIRM:http://support.apple.com/kb/HT4456 | View |
478957 | 43971 | CVE-2010-1387 | APPLE:APPLE-SA-2010-06-16-1 | View |
478958 | 43971 | CVE-2010-1387 | URL:http://lists.apple.com/archives/security-announce/2010//Jun/msg00002.html | View |
478959 | 43971 | CVE-2010-1387 | APPLE:APPLE-SA-2010-06-21-1 | View |
478960 | 43971 | CVE-2010-1387 | URL:http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html | View |
478961 | 43971 | CVE-2010-1387 | APPLE:APPLE-SA-2010-11-22-1 | View |
478962 | 43971 | CVE-2010-1387 | URL:http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html | View |
478963 | 43971 | CVE-2010-1387 | MANDRIVA:MDVSA-2011:039 | View |
478964 | 43971 | CVE-2010-1387 | URL:http://www.mandriva.com/security/advisories?name=MDVSA-2011:039 | View |
478965 | 43971 | CVE-2010-1387 | SUSE:SUSE-SR:2011:002 | View |
478966 | 43971 | CVE-2010-1387 | URL:http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html | View |
478967 | 43971 | CVE-2010-1387 | UBUNTU:USN-1006-1 | View |
478968 | 43971 | CVE-2010-1387 | URL:http://www.ubuntu.com/usn/USN-1006-1 | View |
478969 | 43971 | CVE-2010-1387 | BID:41016 | View |
478970 | 43971 | CVE-2010-1387 | URL:http://www.securityfocus.com/bid/41016 | View |
478971 | 43971 | CVE-2010-1387 | OVAL:oval:org.mitre.oval:def:7061 | View |
478972 | 43971 | CVE-2010-1387 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:7061 | View |
478973 | 43971 | CVE-2010-1387 | SECTRACK:1024108 | View |
478974 | 43971 | CVE-2010-1387 | URL:http://securitytracker.com/id?1024108 | View |
478975 | 43971 | CVE-2010-1387 | SECUNIA:40196 | View |
478976 | 43971 | CVE-2010-1387 | URL:http://secunia.com/advisories/40196 | View |
478977 | 43971 | CVE-2010-1387 | SECUNIA:41856 | View |
478978 | 43971 | CVE-2010-1387 | URL:http://secunia.com/advisories/41856 | View |
478979 | 43971 | CVE-2010-1387 | SECUNIA:42314 | View |
478980 | 43971 | CVE-2010-1387 | URL:http://secunia.com/advisories/42314 | View |
478981 | 43971 | CVE-2010-1387 | SECUNIA:43068 | View |
478982 | 43971 | CVE-2010-1387 | URL:http://secunia.com/advisories/43068 | View |
478983 | 43971 | CVE-2010-1387 | VUPEN:ADV-2010-1512 | View |
478984 | 43971 | CVE-2010-1387 | URL:http://www.vupen.com/english/advisories/2010/1512 | View |
478985 | 43971 | CVE-2010-1387 | VUPEN:ADV-2010-2722 | View |
478986 | 43971 | CVE-2010-1387 | URL:http://www.vupen.com/english/advisories/2010/2722 | View |
478987 | 43971 | CVE-2010-1387 | VUPEN:ADV-2011-0212 | View |
478988 | 43971 | CVE-2010-1387 | URL:http://www.vupen.com/english/advisories/2011/0212 | View |
478989 | 43971 | CVE-2010-1387 | VUPEN:ADV-2011-0552 | View |
478990 | 43971 | CVE-2010-1387 | URL:http://www.vupen.com/english/advisories/2011/0552 | View |
478991 | 43971 | CVE-2010-1387 | XF:itunes-webkit-unspecified-var1(59506) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
35764 | JVNDB-2010-001544 | Apple Safari の WebKit におけるディレクトリトラバーサルの脆弱性 | Apple Safari の WebKit 内にあるローカルストレージおよび Web SQL データベースの実装には、URL に %2f または %5c あるいは .. (dot dot) が含まれる際の処理に不備があるため、任意のデータベースファイルを作成される脆弱性が存在します。 | CVE-2010-1391 | 43971 | 4.3 | http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001544.html | View |