CVE-2009-2416
- EPSS 1.81%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 16.06.2026 23:09:24
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
CVE-2009-1724
- EPSS 6.21%
- Veröffentlicht 09.07.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:07:55
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors r...
CVE-2009-1725
- EPSS 6.19%
- Veröffentlicht 09.07.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:07:55
WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character...
CVE-2009-2419
- EPSS 9.07%
- Veröffentlicht 09.07.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:09:24
Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML docume...
CVE-2009-2420
- EPSS 1.07%
- Veröffentlicht 09.07.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:09:24
Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitrary files or cause a denial of service (launch of multiple Windows Explorer instances) via vectors involving an unspecified HTML ta...
- EPSS 2.5%
- Veröffentlicht 09.07.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:09:24
The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a "high-bit character" ...
CVE-2009-1692
- EPSS 4.24%
- Veröffentlicht 19.06.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:07:50
WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows remote attackers to cause a denial of service (memory consumption or device reset) via a web page conta...
CVE-2009-2058
- EPSS 0.97%
- Veröffentlicht 15.06.2009 19:30:05
- Zuletzt bearbeitet 16.06.2026 23:08:40
Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying th...
CVE-2009-2062
- EPSS 1%
- Veröffentlicht 15.06.2009 19:30:05
- Zuletzt bearbeitet 16.06.2026 23:08:41
Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 3...
CVE-2009-2066
- EPSS 1%
- Veröffentlicht 15.06.2009 19:30:05
- Zuletzt bearbeitet 16.06.2026 23:08:41
Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe ...