CVE-2009-0070
- EPSS 1.22%
- Veröffentlicht 08.01.2009 19:30:11
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably have unspecified other impact via the array index of the arguments array ...
- EPSS 10.8%
- Veröffentlicht 02.01.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause a denial of service (memory consumption and browser crash) via a long ALINK attribute in a BODY element in an HTML document.
CVE-2008-4231
- EPSS 7.67%
- Veröffentlicht 25.11.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not properly handle HTML TABLE elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and applicati...
- EPSS 0.88%
- Veröffentlicht 25.11.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundaries of the IFRAME, which allows remote attackers to spoof a user interface via a crafted HTML document.
CVE-2008-4233
- EPSS 1.16%
- Veröffentlicht 25.11.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not isolate the call-approval dialog from the process of launching new applications, which allows remote attackers to make arbitrary phone calls via a crafted...
CVE-2008-3623
- EPSS 19.03%
- Veröffentlicht 17.11.2008 18:18:47
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (applic...
CVE-2008-3644
- EPSS 0.07%
- Veröffentlicht 17.11.2008 18:18:47
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser's page cache.
CVE-2008-4216
- EPSS 0.64%
- Veröffentlicht 17.11.2008 18:18:47
- Zuletzt bearbeitet 09.04.2025 00:30:58
The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files."
- EPSS 5.38%
- Veröffentlicht 16.09.2008 23:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod touch 1.1.4 and 2.0 allows remote attackers to cause a denial of service (browser crash) via a JavaScr...
- EPSS 58.86%
- Veröffentlicht 12.09.2008 16:56:20
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.