CVE-2010-0661
- EPSS 1.62%
- Veröffentlicht 18.02.2010 18:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.
CVE-2010-0647
- EPSS 10.17%
- Veröffentlicht 18.02.2010 18:00:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
WebKit before r53525, as used in Google Chrome before 4.0.249.89, allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed RUBY element, as demonstrated by a <ruby>><table><rt> sequence.
CVE-2010-0651
- EPSS 2.26%
- Veröffentlicht 18.02.2010 18:00:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, whi...
CVE-2010-0656
- EPSS 0.61%
- Veröffentlicht 18.02.2010 18:00:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a directory, which allows attackers to obtain sensitive information or possibl...
CVE-2010-0659
- EPSS 6.98%
- Veröffentlicht 18.02.2010 18:00:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The image decoder in WebKit before r52833, as used in Google Chrome before 4.0.249.78, does not properly handle a failure of memory allocation, which allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed GIF file tha...
CVE-2008-1025
- EPSS 1.13%
- Veröffentlicht 17.04.2008 19:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a colon in the hostname portion.
CVE-2007-3944
- EPSS 36.79%
- Veröffentlicht 23.07.2007 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions (PCRE) library in the JavaScript engine in WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, allow remote attackers to execute arbitrary code vi...
CVE-2007-0342
- EPSS 5.22%
- Veröffentlicht 18.01.2007 02:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 1...