CVE-2009-2200
- EPSS 0.42%
- Veröffentlicht 12.08.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted ...
CVE-2009-2416
- EPSS 0.19%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
CVE-2009-1724
- EPSS 1.52%
- Veröffentlicht 09.07.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors r...
CVE-2009-1725
- EPSS 12.2%
- Veröffentlicht 09.07.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character...
CVE-2009-2419
- EPSS 28.63%
- Veröffentlicht 09.07.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML docume...
CVE-2009-2420
- EPSS 0.44%
- Veröffentlicht 09.07.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitrary files or cause a denial of service (launch of multiple Windows Explorer instances) via vectors involving an unspecified HTML ta...
- EPSS 1.57%
- Veröffentlicht 09.07.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a "high-bit character" ...
CVE-2009-1692
- EPSS 4.27%
- Veröffentlicht 19.06.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows remote attackers to cause a denial of service (memory consumption or device reset) via a web page conta...
CVE-2009-2058
- EPSS 0.27%
- Veröffentlicht 15.06.2009 19:30:05
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying th...
CVE-2009-2062
- EPSS 0.3%
- Veröffentlicht 15.06.2009 19:30:05
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 3...