Show filters
231 Total Results
Displaying 201-210 of 231
Sort by:
Attacker Value
Unknown
CVE-2009-1684
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via an event handler that triggers script execution in the context of the next loaded document.
0
Attacker Value
Unknown
CVE-2009-1694
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read images from arbitrary web sites via vectors involving a CANVAS element and redirection, related to a "cross-site image capture issue."
0
Attacker Value
Unknown
CVE-2009-1687
Disclosure Date: June 10, 2009 (last updated October 04, 2023)
The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle allocation failures, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document that triggers write access to an "offset of a NULL pointer."
0
Attacker Value
Unknown
CVE-2009-0945
Disclosure Date: May 13, 2009 (last updated October 04, 2023)
Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4) SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object, which triggers memory corruption.
0
Attacker Value
Unknown
CVE-2009-0162
Disclosure Date: May 13, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote attackers to inject arbitrary web script or HTML via a crafted feed: URL.
0
Attacker Value
Unknown
CVE-2008-4233
Disclosure Date: November 25, 2008 (last updated October 04, 2023)
Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not isolate the call-approval dialog from the process of launching new applications, which allows remote attackers to make arbitrary phone calls via a crafted HTML document.
0
Attacker Value
Unknown
CVE-2008-4231
Disclosure Date: November 25, 2008 (last updated October 04, 2023)
Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not properly handle HTML TABLE elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
0
Attacker Value
Unknown
CVE-2008-4232
Disclosure Date: November 25, 2008 (last updated October 04, 2023)
Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundaries of the IFRAME, which allows remote attackers to spoof a user interface via a crafted HTML document.
0
Attacker Value
Unknown
CVE-2008-3623
Disclosure Date: November 17, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image, related to improper handling of color spaces.
0
Attacker Value
Unknown
CVE-2008-3644
Disclosure Date: November 17, 2008 (last updated October 04, 2023)
Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser's page cache.
0