- EPSS 0.38%
- Veröffentlicht 03.12.2006 19:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The AutoFill feature in Apple Safari 2.0.4 does not properly verify that all automatically populated form fields are visible to the user, which allows remote attackers to obtain sensitive information, such as usernames and passwords, via input fields...
CVE-2006-3946
- EPSS 4.72%
- Veröffentlicht 31.07.2006 23:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
WebCore in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted HTML that triggers a "memory management error" in WebKit, possibly due to a buffer o...
- EPSS 6.47%
- Veröffentlicht 06.07.2006 20:05:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttributeNode function call with zero arguments, which triggers a null dereference.
CVE-2006-3224
- EPSS 0.68%
- Veröffentlicht 26.06.2006 16:05:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service (CPU consumption) via Javascript with an infinite for loop. NOTE: it could be argued that this is not a vulnerability, unless it interferes with the...
- EPSS 16.38%
- Veröffentlicht 25.04.2006 17:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a TD element with a large number in the rowspan attribute.
CVE-2006-1985
- EPSS 22.17%
- Veröffentlicht 21.04.2006 22:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which trigger...
CVE-2006-1986
- EPSS 4.52%
- Veröffentlicht 21.04.2006 22:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via a large CELLSPACING attribute in a TABLE tag, which triggers an error in KWQListIteratorImpl::KWQListIteratorImpl.
CVE-2006-1987
- EPSS 4.52%
- Veröffentlicht 21.04.2006 22:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a SRC attribute with no value. NOTE: due to lack of ...
- EPSS 1.43%
- Veröffentlicht 21.04.2006 22:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows remote attackers to cause a denial of service (application crash) via an HTML LI tag with a large VALUE attribute (list item number), which triggers a ...
- EPSS 3.82%
- Veröffentlicht 31.03.2006 11:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".