Apple Security Advisories · May 2010 — Apple Security Advisories
5 advisories 5 CVEs

Apple-vendor CVEs for 2010-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2010-0538

macOSPoC exploitCRITICAL2010-05-19

Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 do not properly handle mediaLibImage objects, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and ...

CVEs:CVE-2010-0538

Affected products

ProductStatusVendorPackageEcosystem
java affected apple
Upstream advisory

CVE-2010-0539

macOSPoC exploitCRITICAL2010-05-19

Integer signedness error in the window drawing implementation in Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) ...

CVEs:CVE-2010-0539

Affected products

ProductStatusVendorPackageEcosystem
java_1.5 affected apple
java_1.6 affected apple
Upstream advisory

CVE-2010-1939

SafariEPSS <= 49%CRITICAL2010-05-13

Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers...

CVEs:CVE-2010-1939

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2010-1729

SafariEPSS <= 49%HIGH2010-05-05

WebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari, allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop.

CVEs:CVE-2010-1729

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
webkit affected apple
Upstream advisory

CVE-2010-1940

SafariEPSS <= 49%CRITICAL2010-05-14

Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by loggi...

CVEs:CVE-2010-1940

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.