Unrated severityNVD Advisory· Published Jul 22, 2010· Updated Apr 29, 2026
CVE-2010-1766
CVE-2010-1766
Description
Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an upgrade header that is long and invalid.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- secunia.com/advisories/40557nvdVendor Advisory
- secunia.com/advisories/41856nvdVendor Advisory
- secunia.com/advisories/43068nvdVendor Advisory
- www.vupen.com/english/advisories/2010/1801nvdVendor Advisory
- lists.fedoraproject.org/pipermail/package-announce/2010-July/044023.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-July/044031.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlnvd
- trac.webkit.org/changeset/56380nvd
- www.mandriva.com/security/advisoriesnvd
- www.ubuntu.com/usn/USN-1006-1nvd
- www.vupen.com/english/advisories/2010/2722nvd
- www.vupen.com/english/advisories/2011/0212nvd
- www.vupen.com/english/advisories/2011/0552nvd
- bugs.webkit.org/show_bug.cginvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.