CVE-2010-1404: WebKit: use-after-free vulnerability in handling of SVG documents with multiple 'use' elements (ZDI-CAN-711)

Severity: Critical

CVSS Score: 9.3

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG document that contains recursive Use elements, which are not properly handled during page deconstruction.