Apple

Safari

1647 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 23.37%
  • Veröffentlicht 12.09.2008 16:56:20
  • Zuletzt bearbeitet 16.06.2026 22:55:59

Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.

  • EPSS 2.51%
  • Veröffentlicht 27.08.2008 20:41:00
  • Zuletzt bearbeitet 16.06.2026 22:55:31

libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.

  • EPSS 2.07%
  • Veröffentlicht 14.07.2008 23:41:00
  • Zuletzt bearbeitet 16.06.2026 22:55:17

Apple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cooking," a relat...

  • EPSS 1.18%
  • Veröffentlicht 14.07.2008 23:41:00
  • Zuletzt bearbeitet 16.06.2026 22:55:17

Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.

  • EPSS 2.27%
  • Veröffentlicht 14.07.2008 18:41:00
  • Zuletzt bearbeitet 16.06.2026 22:52:02

Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to spoof the address bar via Unicode ideographic spaces in the URL.

  • EPSS 1.21%
  • Veröffentlicht 14.07.2008 18:41:00
  • Zuletzt bearbeitet 16.06.2026 22:52:02

Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for visiting a web site with a (1) self-signed or (2) invalid certificate, which makes it easier for remote attackers to spoof web site...

  • EPSS 12.99%
  • Veröffentlicht 14.07.2008 18:41:00
  • Zuletzt bearbeitet 16.06.2026 22:53:30

Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an ...

  • EPSS 7.7%
  • Veröffentlicht 14.07.2008 18:41:00
  • Zuletzt bearbeitet 16.06.2026 22:53:32

WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via a reference to the ...

  • EPSS 3.81%
  • Veröffentlicht 23.06.2008 20:41:00
  • Zuletzt bearbeitet 16.06.2026 22:53:30

Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows remote attackers to bypass intended access restrictions, and force a client system to download and exec...

  • EPSS 7.33%
  • Veröffentlicht 23.06.2008 20:41:00
  • Zuletzt bearbeitet 16.06.2026 22:53:30

Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 10.4, allows remote attackers to cause a denial of service (application crash) or execute arbitrary co...