← Back

CVE-2010-1391

nvd nist
Published: Jun 11, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Multiple directory traversal vulnerabilities in the (a) Local Storage and (b) Web SQL database implementations in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allow remote attackers to create arbitrary database files via vectors involving a (1) %2f and .. (dot dot) or (2) %5c and .. (dot dot) in a URL.

Affected (8)

Products: Apple: Safari, Webkit
2 products
Safari
Webkit
Configuration A
32 platform
Running on/withPlatform Versions
Apple
Mac Os X
Version 10.5.0
Apple
Mac Os X
Version 10.5.1
Apple
Mac Os X
Version 10.5.2
Apple
Mac Os X
Version 10.5.3
Apple
Mac Os X
Version 10.5.4
Apple
Mac Os X
Version 10.5.5
Apple
Mac Os X
Version 10.5.6
Apple
Mac Os X
Version 10.5.7
Apple
Mac Os X
Version 10.5.8
Apple
Mac Os X
Version 10.5
Apple
Mac Os X
Version 10.6.0
Apple
Mac Os X
Version 10.6.1
Apple
Mac Os X
Version 10.6.2
Apple
Mac Os X
Version 10.6.3
Apple
Mac Os X Server
Version 10.5.0
Apple
Mac Os X Server
Version 10.5.1
Apple
Mac Os X Server
Version 10.5.2
Apple
Mac Os X Server
Version 10.5.3
Apple
Mac Os X Server
Version 10.5.4
Apple
Mac Os X Server
Version 10.5.5
Apple
Mac Os X Server
Version 10.5.6
Apple
Mac Os X Server
Version 10.5.7
Apple
Mac Os X Server
Version 10.5.8
Apple
Mac Os X Server
Version 10.5
Apple
Mac Os X Server
Version 10.6.0
Apple
Mac Os X Server
Version 10.6.1
Apple
Mac Os X Server
Version 10.6.2
Apple
Mac Os X Server
Version 10.6.3
Microsoft
Windows 7
All versions
Microsoft
Windows Vista
All versions
Microsoft
Windows Xp
All versions
Microsoft
Windows Xp
All versions
Configuration B
8 vulnerable · 26 platform
Vulnerable SoftwareAffected Versions
Apple
Up to 4.0.5
Version 4.0.0b
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.0
All versions
Running on/withPlatform Versions
Apple
Mac Os X
Version 10.4.0
Apple
Mac Os X
Version 10.4.10
Apple
Mac Os X
Version 10.4.11
Apple
Mac Os X
Version 10.4.1
Apple
Mac Os X
Version 10.4.2
Apple
Mac Os X
Version 10.4.3
Apple
Mac Os X
Version 10.4.4
Apple
Mac Os X
Version 10.4.5
Apple
Mac Os X
Version 10.4.6
Apple
Mac Os X
Version 10.4.7
Apple
Mac Os X
Version 10.4.8
Apple
Mac Os X
Version 10.4.9
Apple
Mac Os X
Version 10.4
Apple
Mac Os X Server
Version 10.4.0
Apple
Mac Os X Server
Version 10.4.10
Apple
Mac Os X Server
Version 10.4.11
Apple
Mac Os X Server
Version 10.4.1
Apple
Mac Os X Server
Version 10.4.2
Apple
Mac Os X Server
Version 10.4.3
Apple
Mac Os X Server
Version 10.4.4
Apple
Mac Os X Server
Version 10.4.5
Apple
Mac Os X Server
Version 10.4.6
Apple
Mac Os X Server
Version 10.4.7
Apple
Mac Os X Server
Version 10.4.8
Apple
Mac Os X Server
Version 10.4.9
Apple
Mac Os X Server
Version 10.4

References (36)

Source: product-security@apple.com
PatchVendor Advisory
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Source: product-security@apple.com
Source: product-security@apple.com
Source: product-security@apple.com
Vendor Advisory
Source: product-security@apple.com
Source: product-security@apple.com
Patch
Source: product-security@apple.com
Source: product-security@apple.com
Source: product-security@apple.com
PatchVendor Advisory
Source: product-security@apple.com
Source: product-security@apple.com
Source: product-security@apple.com
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.