CVE-2010-1401: WebKit: use-after-free vulnerability in handling of the ':first-letter' pseudo-element in CSS (ZDI-CAN-689)

Severity: Critical

CVSS Score: 9.3

Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving the :first-letter pseudo-element.