Apple

Safari

1536 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.84%
  • Veröffentlicht 11.06.2010 18:00:20
  • Zuletzt bearbeitet 11.04.2025 00:51:21

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6, and before 4.1 on Mac OS X 10.4, does not properly handle clipboard (1) drag and (2) paste operations for URLs, which allows user-assisted remote attackers to read arbitrary files via a...

  • EPSS 0.98%
  • Veröffentlicht 11.06.2010 18:00:20
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involvi...

  • EPSS 1.28%
  • Veröffentlicht 11.06.2010 18:00:15
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not provide a warning about a (1) http or (2) https URL that contains a username and password, which makes it easier for remote attackers to cond...

  • EPSS 3.27%
  • Veröffentlicht 11.06.2010 18:00:15
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF d...

  • EPSS 0.26%
  • Veröffentlicht 14.05.2010 20:30:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by log...

Exploit
  • EPSS 50.72%
  • Veröffentlicht 13.05.2010 22:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which trigge...

Exploit
  • EPSS 0.64%
  • Veröffentlicht 06.05.2010 14:53:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

WebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari, allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop.

Exploit
  • EPSS 4.45%
  • Veröffentlicht 29.03.2010 19:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to an array of long strings, an array of IMG elements with crafted strings ...

Exploit
  • EPSS 4.44%
  • Veröffentlicht 29.03.2010 19:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings.

Exploit
  • EPSS 0.45%
  • Veröffentlicht 29.03.2010 19:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) via a JavaScript loop that attempts to construct an infinitely long string.