Show filters
244 Total Results
Displaying 171-180 of 244
Sort by:
Attacker Value
Unknown
CVE-2009-2066
Disclosure Date: June 15, 2009 (last updated October 04, 2023)
Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."
0
Attacker Value
Unknown
CVE-2009-1714
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to the improper escaping of HTML attributes.
0
Attacker Value
Unknown
CVE-2009-1698
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
0
Attacker Value
Unknown
CVE-2009-1716
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
CFNetwork in Apple Safari before 4.0 on Windows does not properly protect the temporary files created for downloads, which allows local users to obtain sensitive information by reading these files.
0
Attacker Value
Unknown
CVE-2009-1709
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and unspecified "caches."
0
Attacker Value
Unknown
CVE-2009-1713
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-1697
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
CRLF injection vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject HTTP headers and bypass the Same Origin Policy via a crafted HTML document, related to cross-site scripting (XSS) attacks that depend on communication with arbitrary web sites on the same server through use of XMLHttpRequest without a Host header.
0
Attacker Value
Unknown
CVE-2009-1718
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive information via vectors involving drag events and the dragging of content over a crafted web page.
0
Attacker Value
Unknown
CVE-2009-1701
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by destroying a document.body element that has an unspecified XML container with elements that support the dir attribute.
0
Attacker Value
Unknown
CVE-2009-1695
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving access to frame contents after completion of a page transition.
0