CVE-2007-0646
- EPSS 16.78%
- Veröffentlicht 01.02.2007 00:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled wh...
CVE-2007-0478
- EPSS 2.54%
- Veröffentlicht 25.01.2007 00:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding ...
CVE-2007-0342
- EPSS 5.22%
- Veröffentlicht 18.01.2007 02:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 1...
- EPSS 0.38%
- Veröffentlicht 03.12.2006 19:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The AutoFill feature in Apple Safari 2.0.4 does not properly verify that all automatically populated form fields are visible to the user, which allows remote attackers to obtain sensitive information, such as usernames and passwords, via input fields...
CVE-2006-3946
- EPSS 4.72%
- Veröffentlicht 31.07.2006 23:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
WebCore in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted HTML that triggers a "memory management error" in WebKit, possibly due to a buffer o...
- EPSS 6.47%
- Veröffentlicht 06.07.2006 20:05:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttributeNode function call with zero arguments, which triggers a null dereference.
CVE-2006-3224
- EPSS 0.68%
- Veröffentlicht 26.06.2006 16:05:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service (CPU consumption) via Javascript with an infinite for loop. NOTE: it could be argued that this is not a vulnerability, unless it interferes with the...
- EPSS 16.38%
- Veröffentlicht 25.04.2006 17:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a TD element with a large number in the rowspan attribute.
CVE-2006-1985
- EPSS 22.17%
- Veröffentlicht 21.04.2006 22:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which trigger...
CVE-2006-1986
- EPSS 4.52%
- Veröffentlicht 21.04.2006 22:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via a large CELLSPACING attribute in a TABLE tag, which triggers an error in KWQListIteratorImpl::KWQListIteratorImpl.