Show filters
219 Total Results
Displaying 211-219 of 219
Sort by:
Attacker Value
Unknown

CVE-2008-4216

Disclosure Date: November 17, 2008 (last updated October 04, 2023)
The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files."
0
Attacker Value
Unknown

CVE-2008-2307

Disclosure Date: June 23, 2008 (last updated October 04, 2023)
Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 10.4, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors involving JavaScript arrays that trigger memory corruption.
0
Attacker Value
Unknown

CVE-2008-2306

Disclosure Date: June 23, 2008 (last updated October 04, 2023)
Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows remote attackers to bypass intended access restrictions, and force a client system to download and execute arbitrary files.
0
Attacker Value
Unknown

CVE-2008-2001

Disclosure Date: April 28, 2008 (last updated October 04, 2023)
Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via a file:///%E2 link that triggers an out-of-bounds access, possibly due to a NULL pointer dereference.
0
Attacker Value
Unknown

CVE-2008-1999

Disclosure Date: April 28, 2008 (last updated October 04, 2023)
Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.
0
Attacker Value
Unknown

CVE-2008-2000

Disclosure Date: April 28, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.
0
Attacker Value
Unknown

CVE-2008-1026

Disclosure Date: April 17, 2008 (last updated October 04, 2023)
Integer overflow in the PCRE regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to execute arbitrary code via a regular expression with large, nested repetition counts, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2008-1025

Disclosure Date: April 17, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a colon in the hostname portion.
0
Attacker Value
Unknown

CVE-2008-1024

Disclosure Date: April 17, 2008 (last updated October 04, 2023)
Apple Safari before 3.1.1, when running on Windows XP or Vista, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file download with a crafted file name, which triggers memory corruption.
0