Critical severity9.8NVD Advisory· Published Apr 3, 2017· Updated May 13, 2026
CVE-2017-5949
CVE-2017-5949
Description
JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers access to red-zone memory locations, related to jit/ThunkGenerators.cpp, llint/LowLevelInterpreter32_64.asm, and llint/LowLevelInterpreter64.asm.
Affected products
1- cpe:2.3:a:apple:safari:22:*:*:*:technology_preview:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/97298nvdThird Party AdvisoryVDB Entry
- bugs.webkit.org/show_bug.cginvdIssue TrackingThird Party Advisory
- trac.webkit.org/changeset/211479nvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.