9.3

CVE-2009-1690

Exploit

Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by setting an unspecified property of an HTML tag that causes child elements to be freed and later accessed when an HTML error occurs, related to "recursion in certain DOM event handlers."

Data is provided by the National Vulnerability Database (NVD)
AppleSafari Editionmac Version <= 4.0_beta
AppleSafari Version0.8 Editionmac
AppleSafari Version0.9 Editionmac
AppleSafari Version1.0 Editionmac
AppleSafari Version1.0.3 Editionmac
AppleSafari Version1.1 Editionmac
AppleSafari Version1.2 Editionmac
AppleSafari Version1.3 Editionmac
AppleSafari Version1.3.1 Editionmac
AppleSafari Version1.3.2 Editionmac
AppleSafari Version2.0 Editionmac
AppleSafari Version2.0.2 Editionmac
AppleSafari Version2.0.4 Editionmac
AppleSafari Version3.0 Editionmac
AppleSafari Version3.0.2 Update- Editionmac
AppleSafari Version3.0.3 Editionmac
AppleSafari Version3.0.4 Editionmac
AppleSafari Version3.1 Editionmac
AppleSafari Version3.1.1 Editionmac
AppleSafari Version3.1.2 Editionmac
AppleSafari Version3.2.1 Editionmac
AppleSafari Version3.2.3 Editionmac
AppleSafari Editionwindows Version <= 3.2.3
AppleSafari Version3.0 Editionwindows
AppleSafari Version3.0.1 Editionwindows
AppleSafari Version3.0.2 Editionwindows
AppleSafari Version3.0.3 Editionwindows
AppleSafari Version3.0.4 Editionwindows
AppleSafari Version3.1 Editionwindows
AppleSafari Version3.1.1 Editionwindows
AppleSafari Version3.1.2 Editionwindows
AppleSafari Version3.2 Update- Editionwindows
AppleSafari Version3.2.1 Editionwindows
AppleSafari Version3.2.2 Editionwindows
AppleiPhone OS Version1.0
AppleiPhone OS Version1.0.0
AppleiPhone OS Version1.0.1
AppleiPhone OS Version1.0.1 Update- Editioniphone
AppleiPhone OS Version1.0.2
AppleiPhone OS Version1.0.2 Update- Editioniphone
AppleiPhone OS Version1.1
AppleiPhone OS Version1.1.0
AppleiPhone OS Version1.1.0 Update- Editioniphone
AppleiPhone OS Version1.1.0 Update- Editionipodtouch
AppleiPhone OS Version1.1.1
AppleiPhone OS Version1.1.1 Update- Editioniphone
AppleiPhone OS Version1.1.2
AppleiPhone OS Version1.1.2 Update- Editioniphone
AppleiPhone OS Version1.1.2 Update- Editionipodtouch
AppleiPhone OS Version1.1.3
AppleiPhone OS Version1.1.3 Update- Editioniphone
AppleiPhone OS Version1.1.3 Update- Editionipodtouch
AppleiPhone OS Version1.1.4
AppleiPhone OS Version1.1.4 Update- Editioniphone
AppleiPhone OS Version1.1.4 Update- Editionipodtouch
AppleiPhone OS Version1.1.5
AppleiPhone OS Version1.1.5 Update- Editioniphone
AppleiPhone OS Version1.1.5 Update- Editionipodtouch
AppleiPhone OS Version2.0
AppleiPhone OS Version2.0.0
AppleiPhone OS Version2.0.0 Update- Editioniphone
AppleiPhone OS Version2.0.0 Update- Editionipodtouch
AppleiPhone OS Version2.0.1
AppleiPhone OS Version2.0.1 Update- Editioniphone
AppleiPhone OS Version2.0.1 Update- Editionipodtouch
AppleiPhone OS Version2.0.2
AppleiPhone OS Version2.0.2 Update- Editioniphone
AppleiPhone OS Version2.0.2 Update- Editionipodtouch
AppleiPhone OS Version2.1
AppleiPhone OS Version2.1 Update- Editioniphone
AppleiPhone OS Version2.1 Update- Editionipodtouch
AppleiPhone OS Version2.2 Update- Editioniphone
AppleiPhone OS Version2.2 Update- Editionipodtouch
AppleiPhone OS Version2.2.1 Update- Editioniphone
AppleiPhone OS Version2.2.1 Update- Editionipodtouch
GoogleChrome Version1.0.154.53
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 12.22% 0.936
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
http://support.apple.com/kb/HT3613
Patch
Vendor Advisory
http://support.apple.com/kb/HT3639
Patch
Vendor Advisory