Apple

Safari

1563 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 8.93%
  • Veröffentlicht 12.06.2007 22:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.

  • EPSS 2.31%
  • Veröffentlicht 12.06.2007 22:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in Apple Safari for Windows allow remote attackers to cause a denial of service or execute arbitrary code, possibly involving memory corruption, and a different issue from CVE-2007-3185 and CVE-2007-3186. NOTE: a...

Exploit
  • EPSS 3.07%
  • Veröffentlicht 24.05.2007 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably inv...

  • EPSS 0.26%
  • Veröffentlicht 09.05.2007 21:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords) via the document.loginform.password.value JavaScript parameter loaded from an AppleScript script.

  • EPSS 85.14%
  • Veröffentlicht 24.04.2007 16:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used ...

  • EPSS 0.56%
  • Veröffentlicht 22.04.2007 19:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Apple Safari allows remote attackers to cause a denial of service (browser crash) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.

  • EPSS 5.22%
  • Veröffentlicht 01.02.2007 00:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in filenames that are not properly handled when calling the (1) NSLog and (2) NSBeginAle...

Exploit
  • EPSS 16.78%
  • Veröffentlicht 01.02.2007 00:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled wh...

  • EPSS 2.54%
  • Veröffentlicht 25.01.2007 00:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding ...

Exploit
  • EPSS 5.22%
  • Veröffentlicht 18.01.2007 02:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 1...