- EPSS 23.37%
- Veröffentlicht 12.09.2008 16:56:20
- Zuletzt bearbeitet 16.06.2026 22:55:59
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
CVE-2008-3281
- EPSS 2.51%
- Veröffentlicht 27.08.2008 20:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:31
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
CVE-2008-3170
- EPSS 2.07%
- Veröffentlicht 14.07.2008 23:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:17
Apple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cooking," a relat...
- EPSS 1.18%
- Veröffentlicht 14.07.2008 23:41:00
- Zuletzt bearbeitet 16.06.2026 22:55:17
Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
CVE-2008-1588
- EPSS 2.27%
- Veröffentlicht 14.07.2008 18:41:00
- Zuletzt bearbeitet 16.06.2026 22:52:02
Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to spoof the address bar via Unicode ideographic spaces in the URL.
CVE-2008-1589
- EPSS 1.21%
- Veröffentlicht 14.07.2008 18:41:00
- Zuletzt bearbeitet 16.06.2026 22:52:02
Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for visiting a web site with a (1) self-signed or (2) invalid certificate, which makes it easier for remote attackers to spoof web site...
- EPSS 12.99%
- Veröffentlicht 14.07.2008 18:41:00
- Zuletzt bearbeitet 16.06.2026 22:53:30
Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an ...
CVE-2008-2317
- EPSS 7.7%
- Veröffentlicht 14.07.2008 18:41:00
- Zuletzt bearbeitet 16.06.2026 22:53:32
WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via a reference to the ...
CVE-2008-2306
- EPSS 3.81%
- Veröffentlicht 23.06.2008 20:41:00
- Zuletzt bearbeitet 16.06.2026 22:53:30
Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows remote attackers to bypass intended access restrictions, and force a client system to download and exec...
CVE-2008-2307
- EPSS 7.33%
- Veröffentlicht 23.06.2008 20:41:00
- Zuletzt bearbeitet 16.06.2026 22:53:30
Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 10.4, allows remote attackers to cause a denial of service (application crash) or execute arbitrary co...