CVE-2010-1388
- EPSS 0.84%
- Published 11.06.2010 18:00:20
- Last modified 11.04.2025 00:51:21
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6, and before 4.1 on Mac OS X 10.4, does not properly handle clipboard (1) drag and (2) paste operations for URLs, which allows user-assisted remote attackers to read arbitrary files via a...
CVE-2010-1389
- EPSS 0.98%
- Published 11.06.2010 18:00:20
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involvi...
CVE-2010-1384
- EPSS 1.28%
- Published 11.06.2010 18:00:15
- Last modified 11.04.2025 00:51:21
Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not provide a warning about a (1) http or (2) https URL that contains a username and password, which makes it easier for remote attackers to cond...
CVE-2010-1385
- EPSS 3.27%
- Published 11.06.2010 18:00:15
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF d...
CVE-2010-1940
- EPSS 0.26%
- Published 14.05.2010 20:30:01
- Last modified 11.04.2025 00:51:21
Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by log...
CVE-2010-1939
- EPSS 50.72%
- Published 13.05.2010 22:30:00
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which trigge...
CVE-2010-1729
- EPSS 0.64%
- Published 06.05.2010 14:53:01
- Last modified 11.04.2025 00:51:21
WebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari, allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop.
CVE-2010-1176
- EPSS 4.45%
- Published 29.03.2010 19:30:00
- Last modified 11.04.2025 00:51:21
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to an array of long strings, an array of IMG elements with crafted strings ...
CVE-2010-1177
- EPSS 4.44%
- Published 29.03.2010 19:30:00
- Last modified 11.04.2025 00:51:21
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings.
CVE-2010-1178
- EPSS 0.45%
- Published 29.03.2010 19:30:00
- Last modified 11.04.2025 00:51:21
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) via a JavaScript loop that attempts to construct an infinitely long string.