CVE Vulnerabilities

CVE-2010-0040

Published: Mar 15, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Integer overflow in ColorSync in Apple Safari before 4.0.5 on Windows, and iTunes before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with a crafted color profile that triggers a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
SafariApple*4.0.4 (including)
SafariApple4.0 (including)4.0 (including)
SafariApple4.0.0b (including)4.0.0b (including)
SafariApple4.0.1 (including)4.0.1 (including)
SafariApple4.0.2 (including)4.0.2 (including)
SafariApple4.0.3 (including)4.0.3 (including)

References