Apple

Safari

1563 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.96%
  • Veröffentlicht 27.09.2007 22:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to "alter or access" HTTPS content via an HTTP session with a crafted web page that...

  • EPSS 1.09%
  • Veröffentlicht 27.09.2007 21:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of the parent window, even when t...

  • EPSS 1.06%
  • Veröffentlicht 27.09.2007 21:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Safari in Apple iPhone 1.1.1 allows remote user-assisted attackers to trick the iPhone user into making calls to arbitrary telephone numbers via a crafted "tel:" link that causes iPhone to display a different number than the number that will be diale...

  • EPSS 4.1%
  • Veröffentlicht 11.09.2007 18:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact by setting document.location.hash to a long string. ...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 20.08.2007 19:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from local zones to external domains, via a certain body.innerHTML property value, aka "classic JavaScript ...

  • EPSS 0.35%
  • Veröffentlicht 18.08.2007 22:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Apple Safari for Windows 3.0.3 and earlier does not prompt the user before downloading a file, which allows remote attackers to download arbitrary files to the desktop of a client system via certain HTML, as demonstrated by a filename in the DATA att...

  • EPSS 0.76%
  • Veröffentlicht 03.08.2007 20:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable Java" setting, which allows remote attackers to execute Java applets via a crafted web page.

Exploit
  • EPSS 0.61%
  • Veröffentlicht 03.08.2007 20:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows remote attackers to create a URL containing "look-ali...

  • EPSS 1.95%
  • Veröffentlicht 03.08.2007 20:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack-based buffer overflow in bookmark handling in Apple Safari 3 Beta before Update 3.0.3 on Windows allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a bookmark with a long title.

  • EPSS 36.79%
  • Veröffentlicht 23.07.2007 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions (PCRE) library in the JavaScript engine in WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, allow remote attackers to execute arbitrary code vi...