Show filters
180 Total Results
Displaying 171-180 of 180
Sort by:
Attacker Value
Unknown
CVE-2008-3644
Disclosure Date: November 17, 2008 (last updated October 04, 2023)
Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser's page cache.
0
Attacker Value
Unknown
CVE-2008-4216
Disclosure Date: November 17, 2008 (last updated October 04, 2023)
The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files."
0
Attacker Value
Unknown
CVE-2008-0298
Disclosure Date: January 16, 2008 (last updated October 04, 2023)
KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involving a STYLE attribute of a DIV element.
0
Attacker Value
Unknown
CVE-2007-3186
Disclosure Date: June 12, 2007 (last updated October 04, 2023)
Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.
0
Attacker Value
Unknown
CVE-2006-3224
Disclosure Date: June 26, 2006 (last updated October 04, 2023)
Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service (CPU consumption) via Javascript with an infinite for loop. NOTE: it could be argued that this is not a vulnerability, unless it interferes with the operation of the system outside of the scope of Safari itself.
0
Attacker Value
Unknown
CVE-2006-2019
Disclosure Date: April 25, 2006 (last updated October 04, 2023)
Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a TD element with a large number in the rowspan attribute.
0
Attacker Value
Unknown
CVE-2006-1985
Disclosure Date: April 21, 2006 (last updated October 04, 2023)
Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which triggers an error in the BOMStackPop function.
0
Attacker Value
Unknown
CVE-2006-1987
Disclosure Date: April 21, 2006 (last updated October 04, 2023)
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a SRC attribute with no value. NOTE: due to lack of diagnosis by the researcher, it is unclear which vector is responsible.
0
Attacker Value
Unknown
CVE-2006-1986
Disclosure Date: April 21, 2006 (last updated October 04, 2023)
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via a large CELLSPACING attribute in a TABLE tag, which triggers an error in KWQListIteratorImpl::KWQListIteratorImpl.
0
Attacker Value
Unknown
CVE-2006-1988
Disclosure Date: April 21, 2006 (last updated October 04, 2023)
The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows remote attackers to cause a denial of service (application crash) via an HTML LI tag with a large VALUE attribute (list item number), which triggers a null dereference in QPainter::drawText, probably due to a failed memory allocation that uses the VALUE.
0