Show filters
195 Total Results
Displaying 181-190 of 195
Sort by:
Attacker Value
Unknown
CVE-2010-0048
Disclosure Date: March 15, 2010 (last updated October 04, 2023)
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XML document.
0
Attacker Value
Unknown
CVE-2010-0040
Disclosure Date: March 15, 2010 (last updated October 04, 2023)
Integer overflow in ColorSync in Apple Safari before 4.0.5 on Windows, and iTunes before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with a crafted color profile that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2010-0043
Disclosure Date: March 15, 2010 (last updated October 04, 2023)
ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image.
0
Attacker Value
Unknown
CVE-2010-0041
Disclosure Date: March 15, 2010 (last updated October 04, 2023)
ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.
0
Attacker Value
Unknown
CVE-2010-0047
Disclosure Date: March 15, 2010 (last updated October 04, 2023)
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "HTML object element fallback content."
0
Attacker Value
Unknown
CVE-2009-3384
Disclosure Date: November 13, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a reply.
0
Attacker Value
Unknown
CVE-2009-2841
Disclosure Date: November 13, 2009 (last updated October 04, 2023)
The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality, aka rdar problem 7271202.
0
Attacker Value
Unknown
CVE-2009-2842
Disclosure Date: November 13, 2009 (last updated October 04, 2023)
Apple Safari before 4.0.4 does not properly implement certain (1) Open Image and (2) Open Link menu options, which allows remote attackers to read local HTML files via a crafted web site.
0
Attacker Value
Unknown
CVE-2009-3455
Disclosure Date: September 29, 2009 (last updated October 04, 2023)
Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
0
Attacker Value
Unknown
CVE-2009-2804
Disclosure Date: September 14, 2009 (last updated October 04, 2023)
Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an image, leading to a heap-based buffer overflow.
0