Unrated severityNVD Advisory· Published Jun 10, 2009· Updated Jun 16, 2026
CVE-2009-1690
CVE-2009-1690
Description
Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by setting an unspecified property of an HTML tag that causes child elements to be freed and later accessed when an HTML error occurs, related to "recursion in certain DOM event handlers."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
83cpe:2.3:a:apple:safari:0.8:*:mac:*:*:*:*:*+ 34 more
- cpe:2.3:a:apple:safari:0.8:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:0.9:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:1.0.3:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:1.0:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:1.1:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:1.2:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:1.3.1:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:1.3.2:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:1.3:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:2.0.2:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:2.0.4:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:2.0:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.0.1:*:windows:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.0.2:-:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.0.2:*:windows:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.0.3:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.0.3:*:windows:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.0.4:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.0.4:*:windows:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.0:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.0:*:windows:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.1.1:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.1.1:*:windows:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.1.2:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.1.2:*:windows:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.1:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.1:*:windows:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.2.1:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.2.1:*:windows:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.2.2:*:windows:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.2.3:*:mac:*:*:*:*:*
- cpe:2.3:a:apple:safari:3.2:-:windows:*:*:*:*:*
- cpe:2.3:a:apple:safari:*:*:mac:*:*:*:*:*range: <=4.0_beta
- cpe:2.3:a:apple:safari:*:*:windows:*:*:*:*:*range: <=3.2.3
- (no CPE)range: <4.0
cpe:2.3:o:apple:iphone_os:1.0:*:*:*:*:*:*:*+ 41 more
- cpe:2.3:o:apple:iphone_os:1.0:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.0.1:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.0.2:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.0:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.0:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.0:-:ipodtouch:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.1:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.2:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.2:-:ipodtouch:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.3:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.3:-:ipodtouch:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.4:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.4:-:ipodtouch:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.5:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.5:-:ipodtouch:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.0:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.0.0:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.0.0:-:ipodtouch:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.0.1:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.0.1:-:ipodtouch:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.0.2:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.0.2:-:ipodtouch:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.1:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.1:-:ipodtouch:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.2.1:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.2.1:-:ipodtouch:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.2:-:iphone:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:2.2:-:ipodtouch:*:*:*:*:*
- (no CPE)range: 1.0 through 2.2.1
- Range: 1.1 through 2.2.1
- osv-coords2 versions
< 4:4.3.0-1+ 1 more
- (no CPE)range: < 4:4.3.0-1
- (no CPE)range: < 4:4.5.2-1
Patches
Vulnerability mechanics
References
28- lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlnvdPatchVendor Advisory
- lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlnvdPatchVendor Advisory
- securitytracker.com/idnvdPatch
- support.apple.com/kb/HT3613nvdPatchVendor Advisory
- support.apple.com/kb/HT3639nvdPatchVendor Advisory
- www.vupen.com/english/advisories/2009/1522nvdPatchVendor Advisory
- www.securityfocus.com/bid/35260nvdExploitPatch
- secunia.com/advisories/35379nvdVendor Advisory
- secunia.com/advisories/36057nvdVendor Advisory
- secunia.com/advisories/36062nvdVendor Advisory
- secunia.com/advisories/36790nvdVendor Advisory
- secunia.com/advisories/37746nvdVendor Advisory
- secunia.com/advisories/43068nvdVendor Advisory
- www.vupen.com/english/advisories/2009/1621nvdVendor Advisory
- www.vupen.com/english/advisories/2011/0212nvdVendor Advisory
- labs.idefense.com/intelligence/vulnerabilities/display.phpnvd
- lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlnvd
- osvdb.org/54990nvd
- www.debian.org/security/2009/dsa-1950nvd
- www.mandriva.com/security/advisoriesnvd
- www.ubuntu.com/usn/USN-822-1nvd
- www.ubuntu.com/usn/USN-836-1nvd
- www.ubuntu.com/usn/USN-857-1nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11009nvd
- www.redhat.com/archives/fedora-package-announce/2009-July/msg01177.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-July/msg01196.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-July/msg01199.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-July/msg01200.htmlnvd
News mentions
0No linked articles in our index yet.