Show filters
204 Total Results
Displaying 161-170 of 204
Sort by:
Attacker Value
Unknown
CVE-2009-2804
Disclosure Date: September 14, 2009 (last updated October 04, 2023)
Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an image, leading to a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2009-2195
Disclosure Date: August 12, 2009 (last updated October 04, 2023)
Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted floating-point numbers.
0
Attacker Value
Unknown
CVE-2009-2200
Disclosure Date: August 12, 2009 (last updated October 04, 2023)
WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.
0
Attacker Value
Unknown
CVE-2009-2199
Disclosure Date: August 12, 2009 (last updated October 04, 2023)
Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified homoglyphs.
0
Attacker Value
Unknown
CVE-2009-1725
Disclosure Date: July 09, 2009 (last updated October 04, 2023)
WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
0
Attacker Value
Unknown
CVE-2009-1724
Disclosure Date: July 09, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors related to parent and top objects.
0
Attacker Value
Unknown
CVE-2009-2027
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
The Installer in Apple Safari before 4.0 on Windows allows local users to gain privileges by checking a box that specifies an immediate launch of the application after installation, related to an unspecified compression method.
0
Attacker Value
Unknown
CVE-2009-1714
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to the improper escaping of HTML attributes.
0
Attacker Value
Unknown
CVE-2009-1698
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
0
Attacker Value
Unknown
CVE-2009-1716
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
CFNetwork in Apple Safari before 4.0 on Windows does not properly protect the temporary files created for downloads, which allows local users to obtain sensitive information by reading these files.
0