6.8

CVE-2009-2804

Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an image, leading to a heap-based buffer overflow.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApplemacOS X Version10.4.11
ApplemacOS X Version10.5.8
ApplemacOS X Server Version10.4.11
ApplemacOS X Server Version10.5.8
AppleSafari Version <= 4.0.3
   MicrosoftWindows
AppleSafari Version0.8
   MicrosoftWindows
AppleSafari Version0.9
   MicrosoftWindows
AppleSafari Version1.0
   MicrosoftWindows
AppleSafari Version1.0 Updatebeta
   MicrosoftWindows
AppleSafari Version1.0 Updatebeta2
   MicrosoftWindows
AppleSafari Version1.0.0
   MicrosoftWindows
AppleSafari Version1.0.0b1
   MicrosoftWindows
AppleSafari Version1.0.0b2
   MicrosoftWindows
AppleSafari Version1.0.1
   MicrosoftWindows
AppleSafari Version1.0.2
   MicrosoftWindows
AppleSafari Version1.0.3
   MicrosoftWindows
AppleSafari Version1.1.0
   MicrosoftWindows
AppleSafari Version1.1.1
   MicrosoftWindows
AppleSafari Version1.2
   MicrosoftWindows
AppleSafari Version1.2.0
   MicrosoftWindows
AppleSafari Version1.2.1
   MicrosoftWindows
AppleSafari Version1.2.2
   MicrosoftWindows
AppleSafari Version1.2.3
   MicrosoftWindows
AppleSafari Version1.2.4
   MicrosoftWindows
AppleSafari Version1.2.5
   MicrosoftWindows
AppleSafari Version1.3
   MicrosoftWindows
AppleSafari Version1.3.0
   MicrosoftWindows
AppleSafari Version1.3.1
   MicrosoftWindows
AppleSafari Version1.3.2
   MicrosoftWindows
AppleSafari Version2
   MicrosoftWindows
AppleSafari Version2.0
   MicrosoftWindows
AppleSafari Version2.0.0
   MicrosoftWindows
AppleSafari Version2.0.1
   MicrosoftWindows
AppleSafari Version2.0.2
   MicrosoftWindows
AppleSafari Version2.0.3
   MicrosoftWindows
AppleSafari Version2.0.3 Update417.8
   MicrosoftWindows
AppleSafari Version2.0.3 Update417.9
   MicrosoftWindows
AppleSafari Version2.0.3 Update417.9.2
   MicrosoftWindows
AppleSafari Version2.0.3 Update417.9.3
   MicrosoftWindows
AppleSafari Version2.0.3_417.9.3
   MicrosoftWindows
AppleSafari Version2.0.4
   MicrosoftWindows
AppleSafari Version2.0.4_419.3
   MicrosoftWindows
AppleSafari Version2.0_pre
   MicrosoftWindows
AppleSafari Version3
   MicrosoftWindows
AppleSafari Version3.0
   MicrosoftWindows
AppleSafari Version3.0.0
   MicrosoftWindows
AppleSafari Version3.0.0b
   MicrosoftWindows
AppleSafari Version3.0.1
   MicrosoftWindows
AppleSafari Version3.0.1 Updatebeta
   MicrosoftWindows
AppleSafari Version3.0.1b
   MicrosoftWindows
AppleSafari Version3.0.2
   MicrosoftWindows
AppleSafari Version3.0.2b
   MicrosoftWindows
AppleSafari Version3.0.3
   MicrosoftWindows
AppleSafari Version3.0.3b
   MicrosoftWindows
AppleSafari Version3.0.4
   MicrosoftWindows
AppleSafari Version3.0.4_beta
   MicrosoftWindows
AppleSafari Version3.0.4b
   MicrosoftWindows
AppleSafari Version3.1
   MicrosoftWindows
AppleSafari Version3.1.0
   MicrosoftWindows
AppleSafari Version3.1.0b
   MicrosoftWindows
AppleSafari Version3.1.1
   MicrosoftWindows
AppleSafari Version3.1.2
   MicrosoftWindows
AppleSafari Version3.2
   MicrosoftWindows
AppleSafari Version3.2.0
   MicrosoftWindows
AppleSafari Version3.2.1
   MicrosoftWindows
AppleSafari Version3.2.2
   MicrosoftWindows
AppleSafari Version3.2.3
   MicrosoftWindows
AppleSafari Version4.0
   MicrosoftWindows
AppleSafari Version4.0 Updatebeta
   MicrosoftWindows
AppleSafari Version4.0.0b
   MicrosoftWindows
AppleSafari Version4.0.1
   MicrosoftWindows
AppleSafari Version4.0.2
   MicrosoftWindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.19% 0.919
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P