Show filters
180 Total Results
Displaying 171-180 of 180
Sort by:
Attacker Value
Unknown

CVE-2008-3644

Disclosure Date: November 17, 2008 (last updated October 04, 2023)
Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser's page cache.
0
Attacker Value
Unknown

CVE-2008-4216

Disclosure Date: November 17, 2008 (last updated October 04, 2023)
The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files."
0
Attacker Value
Unknown

CVE-2008-0298

Disclosure Date: January 16, 2008 (last updated October 04, 2023)
KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involving a STYLE attribute of a DIV element.
0
Attacker Value
Unknown

CVE-2007-3186

Disclosure Date: June 12, 2007 (last updated October 04, 2023)
Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.
0
Attacker Value
Unknown

CVE-2006-3224

Disclosure Date: June 26, 2006 (last updated October 04, 2023)
Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service (CPU consumption) via Javascript with an infinite for loop. NOTE: it could be argued that this is not a vulnerability, unless it interferes with the operation of the system outside of the scope of Safari itself.
0
Attacker Value
Unknown

CVE-2006-2019

Disclosure Date: April 25, 2006 (last updated October 04, 2023)
Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a TD element with a large number in the rowspan attribute.
0
Attacker Value
Unknown

CVE-2006-1985

Disclosure Date: April 21, 2006 (last updated October 04, 2023)
Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which triggers an error in the BOMStackPop function.
0
Attacker Value
Unknown

CVE-2006-1987

Disclosure Date: April 21, 2006 (last updated October 04, 2023)
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a SRC attribute with no value. NOTE: due to lack of diagnosis by the researcher, it is unclear which vector is responsible.
0
Attacker Value
Unknown

CVE-2006-1986

Disclosure Date: April 21, 2006 (last updated October 04, 2023)
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via a large CELLSPACING attribute in a TABLE tag, which triggers an error in KWQListIteratorImpl::KWQListIteratorImpl.
0
Attacker Value
Unknown

CVE-2006-1988

Disclosure Date: April 21, 2006 (last updated October 04, 2023)
The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows remote attackers to cause a denial of service (application crash) via an HTML LI tag with a large VALUE attribute (list item number), which triggers a null dereference in QPainter::drawText, probably due to a failed memory allocation that uses the VALUE.
0