« Volver al listado

CVE-2010-1814

Estado: ModificadaMedia (6.8)—

WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving form menus.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-1814",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@apple.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-09-09T22:00:01.797",
  "references": [
    {
      "url": "http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.html",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://secunia.com/advisories/41856",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://secunia.com/advisories/42314",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://secunia.com/advisories/43068",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://secunia.com/advisories/43086",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://support.apple.com/kb/HT4334",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://support.apple.com/kb/HT4455",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://support.apple.com/kb/HT4456",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:039",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2011-0177.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/43083",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1006-1",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/2722",
      "tags": [
        "Third Party Advisory",
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0212",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0216",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0552",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/61701",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "product-security@apple.com"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.html",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2010//Sep/msg00002.html",
      "tags": [
        "Mailing List",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/41856",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/42314",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/43068",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/43086",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.apple.com/kb/HT4334",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.apple.com/kb/HT4455",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.apple.com/kb/HT4456",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:039",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2011-0177.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/43083",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-1006-1",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/2722",
      "tags": [
        "Third Party Advisory",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0212",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0216",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2011/0552",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/61701",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving form menus."
    },
    {
      "lang": "es",
      "value": "WebKit en Apple OI anterior a v4.1 en el iPhone y el iPod touch permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria y caída de la aplicación) a través de vectores que implican form menus."
    }
  ],
  "lastModified": "2026-06-16T23:19:23.567",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52D67004-A069-4868-9C17-C252032F4F1E",
              "versionEndExcluding": "4.1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:apple:ipod_touch:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F9F4CB31-584D-4810-A35C-31D5702853C9"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B5415705-33E5-46D5-8E4D-9EBADC8C5705"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66B27F2F-BE67-4212-AA9A-454677D56C47",
              "versionEndExcluding": "1.2.6"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2BCB73E-27BB-4878-AD9C-90C4F20C25A0"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D37DF0F-F863-45AC-853A-3E04F9FEC7CA"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87614B58-24AB-49FB-9C84-E8DDBA16353B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "product-security@apple.com"
}