9.3

CVE-2009-1698

Exploit

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AppleSafari Version <= 3.2.2
AppleSafari Version2.0
AppleSafari Version2.0.0
AppleSafari Version2.0.1
AppleSafari Version2.0.2
AppleSafari Version2.0.3
AppleSafari Version2.0.3 Update417.8
AppleSafari Version2.0.3 Update417.9
AppleSafari Version2.0.3 Update417.9.2
AppleSafari Version2.0.3 Update417.9.3
AppleSafari Version2.0.4
AppleSafari Version3.0
AppleSafari Version3.0.0
AppleSafari Version3.0.0b
AppleSafari Version3.0.1
AppleSafari Version3.0.1 Updatebeta
AppleSafari Version3.0.1b
AppleSafari Version3.0.2
AppleSafari Version3.0.2b
AppleSafari Version3.0.3
AppleSafari Version3.0.3b
AppleSafari Version3.0.4
AppleSafari Version3.0.4b
AppleSafari Version3.1.0
AppleSafari Version3.1.0b
AppleSafari Version3.1.1
AppleSafari Version3.1.2
AppleSafari Version3.2.0
AppleSafari Version3.2.1
AppleiPhone OS Version1.0.0
AppleiPhone OS Version1.0.1
AppleiPhone OS Version1.0.2
AppleiPhone OS Version1.1.0
AppleiPhone OS Version1.1.1
AppleiPhone OS Version1.1.2
AppleiPhone OS Version1.1.3
AppleiPhone OS Version1.1.4
AppleiPhone OS Version1.1.5
AppleiPhone OS Version2.0
AppleiPhone OS Version2.0.0
AppleiPhone OS Version2.0.1
AppleiPhone OS Version2.0.2
AppleiPhone OS Version2.1
AppleiPhone OS Version2.1.1
AppleiPhone OS Version2.2
AppleiPhone OS Version2.2.1
AppleiPhone OS Version1.1.0
AppleiPhone OS Version1.1.1
AppleiPhone OS Version1.1.2
AppleiPhone OS Version1.1.3
AppleiPhone OS Version1.1.4
AppleiPhone OS Version1.1.5
AppleiPhone OS Version2.0
AppleiPhone OS Version2.0.0
AppleiPhone OS Version2.0.1
AppleiPhone OS Version2.0.2
AppleiPhone OS Version2.1
AppleiPhone OS Version2.1.1
AppleiPhone OS Version2.2
AppleiPhone OS Version2.2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.36% 0.913
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://support.apple.com/kb/HT3613
Patch
Vendor Advisory