Show filters
242 Total Results
Displaying 231-240 of 242
Sort by:
Attacker Value
Unknown

CVE-2007-3944

Disclosure Date: July 23, 2007 (last updated October 04, 2023)
Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions (PCRE) library in the JavaScript engine in WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, allow remote attackers to execute arbitrary code via certain JavaScript regular expressions. NOTE: this issue was originally reported only for MobileSafari on the iPhone. NOTE: it is not clear whether this stems from an issue in the original distribution of PCRE, which might already have a separate CVE identifier.
0
Attacker Value
Unknown

CVE-2007-3718

Disclosure Date: July 12, 2007 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in the SVG parsing engine in Apple Safari 3 Beta for Windows have unspecified remote attack vectors and impact. NOTE: this issue contains no actionable information, but it was released by a reliable researcher.
0
Attacker Value
Unknown

CVE-2007-3514

Disclosure Date: July 03, 2007 (last updated October 04, 2023)
Cross-domain vulnerability in Apple Safari for Windows 3.0.2 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute to a file:// location, a different vector than CVE-2007-3482.
0
Attacker Value
Unknown

CVE-2007-3376

Disclosure Date: June 25, 2007 (last updated October 04, 2023)
Buffer overflow in Apple Safari 3.0.2 on Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long value in the title HTML tag, which triggers the overflow when the user adds the page as a bookmark.
0
Attacker Value
Unknown

CVE-2007-2400

Disclosure Date: June 25, 2007 (last updated October 04, 2023)
Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.
0
Attacker Value
Unknown

CVE-2007-2398

Disclosure Date: June 21, 2007 (last updated October 04, 2023)
Apple Safari 3.0.1 beta (522.12.12) on Windows allows remote attackers to modify the window title and address bar while filling the main window with arbitrary content by setting the location bar and using setTimeout() to create an event that modifies the window content, which could facilitate phishing attacks.
0
Attacker Value
Unknown

CVE-2007-3284

Disclosure Date: June 19, 2007 (last updated October 04, 2023)
corefoundation.dll in Apple Safari 3.0.1 (552.12.2) for Windows allows remote attackers to cause a denial of service (crash) via certain forms that trigger errors related to History, possibly involving multiple form fields with the same name.
0
Attacker Value
Unknown

CVE-2007-3274

Disclosure Date: June 19, 2007 (last updated October 04, 2023)
Apple Safari 3.0 and 3.0.1 on Windows XP SP2 allows attackers to cause a denial of service (application crash) via JavaScript that sets the document.location variable, as demonstrated by an empty value of document.location.
0
Attacker Value
Unknown

CVE-2007-2391

Disclosure Date: June 14, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Apple Safari Beta 3.0.1 for Windows allows remote attackers to inject arbitrary web script or HTML via a web page that includes a windows.setTimeout function that is activated after the user has moved from the current page.
0
Attacker Value
Unknown

CVE-2007-3185

Disclosure Date: June 12, 2007 (last updated October 04, 2023)
Apple Safari Beta 3.0.1 for Windows public beta allows remote attackers to cause a denial of service (crash) via unspecified DHTML manipulations that trigger memory corruption, as demonstrated using Hamachi.
0