Show filters
242 Total Results
Displaying 161-170 of 242
Sort by:
Attacker Value
Unknown

CVE-2009-3271

Disclosure Date: September 21, 2009 (last updated October 04, 2023)
Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel: URL in the SRC attribute of an IFRAME element.
0
Attacker Value
Unknown

CVE-2009-2804

Disclosure Date: September 14, 2009 (last updated October 04, 2023)
Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an image, leading to a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2009-2195

Disclosure Date: August 12, 2009 (last updated October 04, 2023)
Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted floating-point numbers.
0
Attacker Value
Unknown

CVE-2009-2200

Disclosure Date: August 12, 2009 (last updated October 04, 2023)
WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.
0
Attacker Value
Unknown

CVE-2009-2199

Disclosure Date: August 12, 2009 (last updated October 04, 2023)
Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified homoglyphs.
0
Attacker Value
Unknown

CVE-2009-2416

Disclosure Date: August 11, 2009 (last updated February 03, 2024)
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
Attacker Value
Unknown

CVE-2009-1725

Disclosure Date: July 09, 2009 (last updated October 04, 2023)
WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
0
Attacker Value
Unknown

CVE-2009-1724

Disclosure Date: July 09, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors related to parent and top objects.
0
Attacker Value
Unknown

CVE-2009-2072

Disclosure Date: June 15, 2009 (last updated October 04, 2023)
Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to spoof an arbitrary https site by sending the browser a crafted (1) 4xx or (2) 5xx CONNECT response page for an https request sent through a proxy server.
0
Attacker Value
Unknown

CVE-2009-2062

Disclosure Date: June 15, 2009 (last updated October 04, 2023)
Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.
0