Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2010-1822

CVE-2010-1822, high severity (CVSS 8.8): 3 tracked apps concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
8.8

NVD scale

Exploitation
2.2 %

EPSS, predicted over 30 days

Tracked apps
3
Still exposed
0

WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3 and Google Chrome before 6.0.472.62, does not properly perform a cast of an unspecified variable, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG element in a non-SVG document.

Attack vector : Network No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS 2.18% above median percentile 81.1%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • Safari macOS com.apple.Safari
    Affected <4.1.3 Fixed in 4.1.3 Latest tracked - undetermined
  • Chrome macOS com.google.Chrome
    Affected <6.0.472.62 Fixed in 6.0.472.62 Latest tracked - undetermined
  • Google Chrome Windows winget:Google.Chrome
    Affected <6.0.472.62 Fixed in 6.0.472.62 Latest tracked 152.0.7977.65 patched
Vulnerable CPE configurations (4)
Vendor Product Versions
apple safari
All platforms (wildcard)
<4.1.3
apple safari
All platforms (wildcard)
≥5.0 <5.0.3
google chrome
All platforms (wildcard)
<6.0.472.62
google chrome
All platforms (wildcard)
<6.0.472.62
View on NVD ↗ Advisory · code.google.com Advisory · googlechromereleases.blogspot.com Advisory · lists.apple.com