Apple

Safari

1655 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.93%
  • Veröffentlicht 11.06.2010 18:00:20
  • Zuletzt bearbeitet 16.06.2026 23:18:15

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involvi...

  • EPSS 2.98%
  • Veröffentlicht 11.06.2010 18:00:15
  • Zuletzt bearbeitet 16.06.2026 23:18:14

Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not provide a warning about a (1) http or (2) https URL that contains a username and password, which makes it easier for remote attackers to cond...

  • EPSS 5.48%
  • Veröffentlicht 11.06.2010 18:00:15
  • Zuletzt bearbeitet 16.06.2026 23:18:15

Use-after-free vulnerability in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF d...

  • EPSS 0.81%
  • Veröffentlicht 14.05.2010 20:30:01
  • Zuletzt bearbeitet 16.06.2026 23:19:37

Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by log...

Exploit
  • EPSS 14.71%
  • Veröffentlicht 13.05.2010 22:30:00
  • Zuletzt bearbeitet 16.06.2026 23:19:37

Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which trigge...

Exploit
  • EPSS 1.98%
  • Veröffentlicht 06.05.2010 14:53:01
  • Zuletzt bearbeitet 16.06.2026 23:19:12

WebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari, allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop.

Exploit
  • EPSS 8.6%
  • Veröffentlicht 29.03.2010 19:30:00
  • Zuletzt bearbeitet 16.06.2026 23:17:46

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to an array of long strings, an array of IMG elements with crafted strings ...

Exploit
  • EPSS 7.23%
  • Veröffentlicht 29.03.2010 19:30:00
  • Zuletzt bearbeitet 16.06.2026 23:17:46

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings.

Exploit
  • EPSS 1.5%
  • Veröffentlicht 29.03.2010 19:30:00
  • Zuletzt bearbeitet 16.06.2026 23:17:46

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) via a JavaScript loop that attempts to construct an infinitely long string.

Exploit
  • EPSS 8.95%
  • Veröffentlicht 29.03.2010 19:30:00
  • Zuletzt bearbeitet 16.06.2026 23:17:46

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large integer in the numcolors attribute of a recolorinfo element in a VML file, possibly...