CVE-2007-0646
- EPSS 16.78%
- Published 01.02.2007 00:28:00
- Last modified 09.04.2025 00:30:58
Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled wh...
CVE-2007-0478
- EPSS 2.54%
- Published 25.01.2007 00:28:00
- Last modified 09.04.2025 00:30:58
WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding ...
CVE-2007-0342
- EPSS 5.22%
- Published 18.01.2007 02:28:00
- Last modified 09.04.2025 00:30:58
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 1...
- EPSS 0.38%
- Published 03.12.2006 19:28:00
- Last modified 09.04.2025 00:30:58
The AutoFill feature in Apple Safari 2.0.4 does not properly verify that all automatically populated form fields are visible to the user, which allows remote attackers to obtain sensitive information, such as usernames and passwords, via input fields...
CVE-2006-3946
- EPSS 4.72%
- Published 31.07.2006 23:04:00
- Last modified 03.04.2025 01:03:51
WebCore in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted HTML that triggers a "memory management error" in WebKit, possibly due to a buffer o...
- EPSS 6.47%
- Published 06.07.2006 20:05:00
- Last modified 03.04.2025 01:03:51
Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttributeNode function call with zero arguments, which triggers a null dereference.
CVE-2006-3224
- EPSS 0.68%
- Published 26.06.2006 16:05:00
- Last modified 03.04.2025 01:03:51
Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service (CPU consumption) via Javascript with an infinite for loop. NOTE: it could be argued that this is not a vulnerability, unless it interferes with the...
- EPSS 16.38%
- Published 25.04.2006 17:06:00
- Last modified 03.04.2025 01:03:51
Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a TD element with a large number in the rowspan attribute.
CVE-2006-1985
- EPSS 22.17%
- Published 21.04.2006 22:02:00
- Last modified 03.04.2025 01:03:51
Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which trigger...
CVE-2006-1986
- EPSS 4.52%
- Published 21.04.2006 22:02:00
- Last modified 03.04.2025 01:03:51
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via a large CELLSPACING attribute in a TABLE tag, which triggers an error in KWQListIteratorImpl::KWQListIteratorImpl.