Show filters
220 Total Results
Displaying 201-210 of 220
Sort by:
Attacker Value
Unknown
CVE-2009-0162
Disclosure Date: May 13, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote attackers to inject arbitrary web script or HTML via a crafted feed: URL.
0
Attacker Value
Unknown
CVE-2008-3623
Disclosure Date: November 17, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image, related to improper handling of color spaces.
0
Attacker Value
Unknown
CVE-2008-3644
Disclosure Date: November 17, 2008 (last updated October 04, 2023)
Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser's page cache.
0
Attacker Value
Unknown
CVE-2008-4216
Disclosure Date: November 17, 2008 (last updated October 04, 2023)
The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files."
0
Attacker Value
Unknown
CVE-2008-3281
Disclosure Date: August 27, 2008 (last updated February 03, 2024)
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
0
Attacker Value
Unknown
CVE-2008-2307
Disclosure Date: June 23, 2008 (last updated October 04, 2023)
Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 10.4, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors involving JavaScript arrays that trigger memory corruption.
0
Attacker Value
Unknown
CVE-2008-2306
Disclosure Date: June 23, 2008 (last updated October 04, 2023)
Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows remote attackers to bypass intended access restrictions, and force a client system to download and execute arbitrary files.
0
Attacker Value
Unknown
CVE-2008-1025
Disclosure Date: April 17, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a colon in the hostname portion.
0
Attacker Value
Unknown
CVE-2008-1004
Disclosure Date: March 19, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the Web Inspector.
0
Attacker Value
Unknown
CVE-2008-1011
Disclosure Date: March 19, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via a frame that calls a method instance in another frame.
0