CVE-2010-0041
Summary
| CVE | CVE-2010-0041 |
|---|---|
| State | PUBLISHED |
| Assigner | apple |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-03-15 13:28:25 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Safari | 4.0 | All | All | All |
| Application | Apple | Safari | 4.0.0b | All | All | All |
| Application | Apple | Safari | 4.0.1 | All | All | All |
| Application | Apple | Safari | 4.0.2 | All | All | All |
| Application | Apple | Safari | 4.0.3 | All | All | All |
| Application | Apple | Safari | All | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apple iTunes Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Apple Safari BMP Image Uninitialized Memory Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| APPLE-SA-2010-03-30-2 iTunes 9.1 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| About the security content of iTunes 9.1 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| About the security content of iOS 4 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| APPLE-SA-2010-03-29-1 Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| APPLE-SA-2010-06-21-1 iOS 4 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| About the security content of Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| SecurityTracker.com Archives - Apple Safari Bugs Let Remote Users Cause Arbitrary Code to Be Executed | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| About the security content of Safari 4.0.5 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Vendor Advisory |
| RETIRED: Apple Safari Prior to 4.0.5 Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| APPLE-SA-2010-03-11-1 Safari 4.0.5 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.