Apple

Safari

1647 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.08%
  • Veröffentlicht 19.06.2007 22:30:00
  • Zuletzt bearbeitet 16.06.2026 22:41:25

corefoundation.dll in Apple Safari 3.0.1 (552.12.2) for Windows allows remote attackers to cause a denial of service (crash) via certain forms that trigger errors related to History, possibly involving multiple form fields with the same name.

  • EPSS 1.01%
  • Veröffentlicht 19.06.2007 21:30:00
  • Zuletzt bearbeitet 16.06.2026 22:41:23

Apple Safari 3.0 and 3.0.1 on Windows XP SP2 allows attackers to cause a denial of service (application crash) via JavaScript that sets the document.location variable, as demonstrated by an empty value of document.location.

  • EPSS 1.29%
  • Veröffentlicht 14.06.2007 18:30:00
  • Zuletzt bearbeitet 16.06.2026 22:39:29

Cross-site scripting (XSS) vulnerability in Apple Safari Beta 3.0.1 for Windows allows remote attackers to inject arbitrary web script or HTML via a web page that includes a windows.setTimeout function that is activated after the user has moved from ...

  • EPSS 1.88%
  • Veröffentlicht 12.06.2007 22:30:00
  • Zuletzt bearbeitet 16.06.2026 22:41:13

Apple Safari Beta 3.0.1 for Windows public beta allows remote attackers to cause a denial of service (crash) via unspecified DHTML manipulations that trigger memory corruption, as demonstrated using Hamachi.

  • EPSS 4.93%
  • Veröffentlicht 12.06.2007 22:30:00
  • Zuletzt bearbeitet 16.06.2026 22:41:14

Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.

  • EPSS 3.22%
  • Veröffentlicht 12.06.2007 22:30:00
  • Zuletzt bearbeitet 16.06.2026 22:41:14

Multiple unspecified vulnerabilities in Apple Safari for Windows allow remote attackers to cause a denial of service or execute arbitrary code, possibly involving memory corruption, and a different issue from CVE-2007-3185 and CVE-2007-3186. NOTE: a...

Exploit
  • EPSS 3.49%
  • Veröffentlicht 24.05.2007 18:30:00
  • Zuletzt bearbeitet 16.06.2026 22:40:32

Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably inv...

  • EPSS 0.74%
  • Veröffentlicht 09.05.2007 21:19:00
  • Zuletzt bearbeitet 16.06.2026 22:39:52

Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords) via the document.loginform.password.value JavaScript parameter loaded from an AppleScript script.

  • EPSS 83.8%
  • Veröffentlicht 24.04.2007 16:19:00
  • Zuletzt bearbeitet 16.06.2026 22:39:04

Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used ...

  • EPSS 1.08%
  • Veröffentlicht 22.04.2007 19:19:00
  • Zuletzt bearbeitet 16.06.2026 22:39:03

Apple Safari allows remote attackers to cause a denial of service (browser crash) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.