CVE-2010-1029
Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for...
- Published
- Mar 19, 2010
- Updated
- Aug 7, 2024
- Assigning CNA
- mitre
- Evidence observed
- Feb 24, 2010
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:PModerate · next 30 days
- Percentile
- 95.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a STYLE element composed of a large number of *> sequences.
Sources
2- Apple Safari 4.0.4 / Google Chrome 4.0.249 - CSS style Stack Overflow Denial of Service (PoC)Exploit
Rad L. Sneak · multiple · Feb 24, 2010
t12 · hardware · Feb 24, 2010
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.