VYPR
Unrated severityNVD Advisory· Published Nov 23, 2004· Updated Apr 16, 2026

CVE-2004-0361

CVE-2004-0361

Description

Safari 1.2 and earlier crashes via JavaScript Array with an extremely large size value, enabling remote denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Safari 1.2 and earlier crashes via JavaScript Array with an extremely large size value, enabling remote denial of service.

Vulnerability

The JavaScript engine in Safari 1.2 and earlier contains an array allocation management error. A remote attacker can cause a denial of service (segmentation fault) by creating a new Array object with a large size value and then writing into that array. Affected versions: Safari ≤ 1.2 [1].

Exploitation

An attacker needs only to craft a malicious web page or HTML content that triggers the vulnerable code path. No special network position beyond the ability to deliver content to the victim's Safari browser is required, and no authentication is needed. The exploit involves executing JavaScript such as var a = new Array(99999999999999999999999); a[0+5]="AAAAA"; [1]. The browser processes the oversized array allocation, leading to a segmentation fault.

Impact

Successful exploitation results in a denial of service: Safari crashes due to a segmentation fault. According to the advisory, there is no known way to execute arbitrary code with this vulnerability as of the publication date [1]. The impact is limited to a crash of the browser, but this could be repeated to persistently deny browser functionality to the user.

Mitigation

No vendor patch was issued within the disclosed timeline; the advisory notes the vendor was notified on 19/03/04 but no fix is referenced [1]. Users should upgrade to a newer version of Safari or consider using an alternative browser. The vulnerability affects Safari ≤ 1.2; later versions fixed the issue. Konqueror does not appear to be vulnerable [1].

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.