Show filters
231 Total Results
Displaying 221-230 of 231
Sort by:
Attacker Value
Unknown

CVE-2008-1007

Disclosure Date: March 19, 2008 (last updated October 04, 2023)
WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown

CVE-2008-1003

Disclosure Date: March 19, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to sites that set the document.domain property or have the same document.domain.
0
Attacker Value
Unknown

CVE-2008-1010

Disclosure Date: March 19, 2008 (last updated October 04, 2023)
Buffer overflow in WebKit, as used in Apple Safari before 3.1, allows remote attackers to execute arbitrary code via crafted regular expressions in JavaScript.
0
Attacker Value
Unknown

CVE-2006-1552

Disclosure Date: March 31, 2006 (last updated February 22, 2025)
Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".
0
Attacker Value
Unknown

CVE-2005-4504

Disclosure Date: December 22, 2005 (last updated February 22, 2025)
The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a large ROWSPAN attribute in a TD tag.
0
Attacker Value
Unknown

CVE-2005-3018

Disclosure Date: September 21, 2005 (last updated February 22, 2025)
Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL.
0
Attacker Value
Unknown

CVE-2004-1314

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than CVE-2004-1122.
0
Attacker Value
Unknown

CVE-2004-1199

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.
0
Attacker Value
Unknown

CVE-2004-1121

Disclosure Date: November 01, 2004 (last updated February 22, 2025)
Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags.
0
Attacker Value
Unknown

CVE-2003-0514

Disclosure Date: April 15, 2004 (last updated February 22, 2025)
Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Safari to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.
0