CVE-2008-4231
- EPSS 7.67%
- Veröffentlicht 25.11.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not properly handle HTML TABLE elements, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and applicati...
- EPSS 0.88%
- Veröffentlicht 25.11.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundaries of the IFRAME, which allows remote attackers to spoof a user interface via a crafted HTML document.
CVE-2008-4233
- EPSS 1.16%
- Veröffentlicht 25.11.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not isolate the call-approval dialog from the process of launching new applications, which allows remote attackers to make arbitrary phone calls via a crafted...
CVE-2008-3623
- EPSS 19.03%
- Veröffentlicht 17.11.2008 18:18:47
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (applic...
CVE-2008-3644
- EPSS 0.07%
- Veröffentlicht 17.11.2008 18:18:47
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser's page cache.
CVE-2008-4216
- EPSS 0.64%
- Veröffentlicht 17.11.2008 18:18:47
- Zuletzt bearbeitet 09.04.2025 00:30:58
The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files."
- EPSS 6.14%
- Veröffentlicht 16.09.2008 23:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod touch 1.1.4 and 2.0 allows remote attackers to cause a denial of service (browser crash) via a JavaScr...
- EPSS 58.86%
- Veröffentlicht 12.09.2008 16:56:20
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
CVE-2008-3281
- EPSS 0.8%
- Veröffentlicht 27.08.2008 20:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
CVE-2008-3170
- EPSS 1.83%
- Veröffentlicht 14.07.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cooking," a relat...