Show filters
165 Total Results
Displaying 91-100 of 165
Sort by:
Attacker Value
Unknown
CVE-2012-0584
Disclosure Date: March 12, 2012 (last updated October 04, 2023)
The Internationalized Domain Name (IDN) feature in Apple Safari before 5.1.4 on Windows does not properly restrict the characters in URLs, which allows remote attackers to spoof a domain name via unspecified homoglyphs.
0
Attacker Value
Unknown
CVE-2012-0640
Disclosure Date: March 12, 2012 (last updated October 04, 2023)
WebKit in Apple Safari before 5.1.4 does not properly implement "From third parties and advertisers" cookie blocking, which makes it easier for remote web servers to track users via a cookie.
0
Attacker Value
Unknown
CVE-2012-0637
Disclosure Date: March 08, 2012 (last updated October 04, 2023)
WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2012-03-07-1.
0
Attacker Value
Unknown
CVE-2012-0636
Disclosure Date: March 08, 2012 (last updated October 04, 2023)
WebKit, as used in Apple iTunes before 10.6, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2012-03-07-1.
0
Attacker Value
Unknown
CVE-2011-3443
Disclosure Date: March 02, 2012 (last updated October 04, 2023)
Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via vectors related to improper list management for Cascading Style Sheets (CSS) @font-face rules.
0
Attacker Value
Unknown
CVE-2010-5070
Disclosure Date: December 07, 2011 (last updated October 04, 2023)
The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method, a different vulnerability than CVE-2010-2264. NOTE: this may overlap CVE-2010-5073.
0
Attacker Value
Unknown
CVE-2011-3230
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via a crafted web site.
0
Attacker Value
Unknown
CVE-2011-3229
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in Apple Safari before 5.1.1 allows remote attackers to execute arbitrary JavaScript code, in a Safari Extensions context, via a crafted safari-extension: URL.
0
Attacker Value
Unknown
CVE-2011-3242
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
The Private Browsing feature in Apple Safari before 5.1.1 on Mac OS X does not properly recognize the Always value of the Block Cookies setting, which makes it easier for remote web servers to track users via a cookie.
0
Attacker Value
Unknown
CVE-2011-3243
Disclosure Date: October 14, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows.
0