VYPR

Safari

by Apple Inc.

CVEs (1,740)

  • CVE-2009-3455Sep 29, 2009
    risk 0.00cvss —epss 0.01

    Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued…

  • CVE-2009-2804Sep 14, 2009
    risk 0.00cvss —epss 0.04

    Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an image, leading to a…

  • CVE-2009-3016Aug 31, 2009
    risk 0.00cvss —epss 0.01

    Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2)…

  • CVE-2009-2200Aug 12, 2009
    risk 0.00cvss —epss 0.02

    WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

  • CVE-2009-2199Aug 12, 2009
    risk 0.00cvss —epss 0.03

    Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified…

  • CVE-2009-2196Aug 12, 2009
    risk 0.00cvss —epss 0.05

    Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors.

  • CVE-2009-2198Aug 4, 2009
    risk 0.00cvss —epss 0.02

    Apple GarageBand before 5.1 reconfigures Safari to accept all cookies regardless of domain name, which makes it easier for remote web servers to track users.

  • CVE-2009-1725Jul 9, 2009
    risk 0.00cvss —epss 0.06

    WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows…

  • CVE-2009-2421Jul 9, 2009
    risk 0.00cvss —epss 0.03

    The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a "high-bit character" in a URL fragment for an…

  • CVE-2009-2420Jul 9, 2009
    risk 0.00cvss —epss 0.01

    Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitrary files or cause a denial of service (launch of multiple Windows Explorer instances) via vectors involving an unspecified HTML tag, possibly a related issue…

  • CVE-2009-1692Jun 19, 2009
    risk 0.00cvss —epss 0.04

    WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows remote attackers to cause a denial of service (memory consumption or device reset) via a web page containing an HTMLSelectElement…

  • CVE-2009-1680Jun 19, 2009
    risk 0.00cvss —epss 0.00

    Safari in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly clear the search history when it is cleared from the Settings application, which allows physically proximate attackers to obtain the search history.

  • CVE-2009-2072Jun 15, 2009
    risk 0.00cvss —epss 0.00

    Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to spoof an arbitrary https site by sending the browser a crafted (1) 4xx or (2) 5xx CONNECT response page for an https request sent…

  • CVE-2009-2066Jun 15, 2009
    risk 0.00cvss —epss 0.01

    Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file…

  • CVE-2009-2062Jun 15, 2009
    risk 0.00cvss —epss 0.01

    Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary…

  • CVE-2009-2058Jun 15, 2009
    risk 0.00cvss —epss 0.01

    Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an…

  • CVE-2009-2027Jun 10, 2009
    risk 0.00cvss —epss 0.00

    The Installer in Apple Safari before 4.0 on Windows allows local users to gain privileges by checking a box that specifies an immediate launch of the application after installation, related to an unspecified compression method.

  • CVE-2009-1718Jun 10, 2009
    risk 0.00cvss —epss 0.02

    WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive information via vectors involving drag events and the dragging of content over a crafted web page.

  • CVE-2009-1716Jun 10, 2009
    risk 0.00cvss —epss 0.00

    CFNetwork in Apple Safari before 4.0 on Windows does not properly protect the temporary files created for downloads, which allows local users to obtain sensitive information by reading these files.

  • CVE-2009-1715Jun 10, 2009
    risk 0.00cvss —epss 0.04

    Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to script execution with incorrect privileges.

Page 81 of 87