VYPR
Unrated severityNVD Advisory· Published Jun 10, 2009· Updated Apr 23, 2026

CVE-2009-1686

CVE-2009-1686

Description

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle constant (aka const) declarations in a type-conversion operation during JavaScript exception handling, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.

Affected products

34
  • Apple Inc./Safari34 versions
    cpe:2.3:a:apple:safari:0.8:-:mac:*:*:*:*:*+ 33 more
    • cpe:2.3:a:apple:safari:0.8:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:0.9:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:1.0.3:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:1.0:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:1.1:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:1.2:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:1.3.1:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:1.3.2:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:1.3:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:2.0.2:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:2.0.4:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:2.0:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.0.1:-:windows:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.0.2:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.0.2:-:windows:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.0.3:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.0.3:-:windows:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.0.4:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.0.4:-:windows:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.0:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.0:-:windows:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.1.1:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.1.1:-:windows:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.1.2:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.1.2:-:windows:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.1:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.1:-:windows:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.2.1:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.2.1:-:windows:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.2.2:-:windows:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.2.3:-:mac:*:*:*:*:*
    • cpe:2.3:a:apple:safari:3.2:-:windows:*:*:*:*:*
    • cpe:2.3:a:apple:safari:*:-:mac:*:*:*:*:*range: <=4.0_beta
    • cpe:2.3:a:apple:safari:*:-:windows:*:*:*:*:*range: <=3.2.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

14

News mentions

0

No linked articles in our index yet.