Apple

Safari

1655 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 8.54%
  • Veröffentlicht 17.04.2009 00:30:00
  • Zuletzt bearbeitet 16.06.2026 23:06:10

Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.

  • EPSS 4.45%
  • Veröffentlicht 02.04.2009 17:30:00
  • Zuletzt bearbeitet 16.06.2026 23:06:49

Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an XML document containing many nested A elements.

  • EPSS 4.55%
  • Veröffentlicht 24.03.2009 14:30:00
  • Zuletzt bearbeitet 16.06.2026 23:06:25

Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Charlie Miller during a PWN2OWN competition at CanSecWest 2009.

  • EPSS 4.68%
  • Veröffentlicht 23.03.2009 14:19:12
  • Zuletzt bearbeitet 16.06.2026 23:06:22

Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.

Exploit
  • EPSS 6.65%
  • Veröffentlicht 27.02.2009 17:30:09
  • Zuletzt bearbeitet 16.06.2026 23:05:41

Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a feeds: URI beginning with a (1) % (percent), (2) { (open curly bracket), (3) } (close curly bracket), (4) ^ (...

  • EPSS 3.2%
  • Veröffentlicht 13.02.2009 00:30:05
  • Zuletzt bearbeitet 16.06.2026 23:04:20

Multiple unspecified vulnerabilities in Safari RSS in Apple Mac OS X 10.4.11 and 10.5.6, and Windows XP and Vista, allow remote attackers to execute arbitrary JavaScript in the local security zone via a crafted feed: URL, related to "input validation...

Exploit
  • EPSS 2.36%
  • Veröffentlicht 28.01.2009 18:30:00
  • Zuletzt bearbeitet 16.06.2026 23:04:45

Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (...

  • EPSS 0.87%
  • Veröffentlicht 20.01.2009 16:30:00
  • Zuletzt bearbeitet 16.06.2026 23:01:13

An unspecified function in the JavaScript implementation in Apple Safari creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed po...

  • EPSS 1.67%
  • Veröffentlicht 15.01.2009 17:30:00
  • Zuletzt bearbeitet 16.06.2026 23:04:18

Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for...

  • EPSS 2.86%
  • Veröffentlicht 08.01.2009 19:30:11
  • Zuletzt bearbeitet 16.06.2026 23:04:12

Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably have unspecified other impact via the array index of the arguments array ...