Apple

Safari

1564 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 29.09.2009 18:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a...

Exploit
  • EPSS 5.16%
  • Veröffentlicht 21.09.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel: URL in the SRC attribute of an IFRAME element.

  • EPSS 4.44%
  • Veröffentlicht 21.09.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls eval on a long string com...

  • EPSS 9.19%
  • Veröffentlicht 14.09.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an ...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 31.08.2009 16:30:07
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contain...

  • EPSS 29.05%
  • Veröffentlicht 12.08.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted floating-point numbers.

  • EPSS 19.51%
  • Veröffentlicht 12.08.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors.

  • EPSS 1.42%
  • Veröffentlicht 12.08.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishi...

  • EPSS 0.42%
  • Veröffentlicht 12.08.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted ...

  • EPSS 0.19%
  • Veröffentlicht 11.08.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...