[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-1687Date: (C)2009-06-10   (M)2024-02-22


The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle allocation failures, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document that triggers write access to an "offset of a NULL pointer."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1022345
BID-35260
BID-35309
SECUNIA-35379
SECUNIA-36057
SECUNIA-36062
SECUNIA-36790
SECUNIA-37746
SECUNIA-43068
OSVDB-54985
ADV-2009-1522
ADV-2009-1621
ADV-2011-0212
APPLE-SA-2009-06-08-1
APPLE-SA-2009-06-17-1
DSA-1950
FEDORA-2009-8020
FEDORA-2009-8039
FEDORA-2009-8046
FEDORA-2009-8049
MDVSA-2009:330
SUSE-SR:2011:002
USN-822-1
USN-836-1
USN-857-1
http://support.apple.com/kb/HT3613
http://support.apple.com/kb/HT3639
oval:org.mitre.oval:def:10260

CPE    1
cpe:/a:apple:safari:3.0.2:-:mac
CWE    1
CWE-399
OVAL    27
oval:org.secpod.oval:def:700364
oval:org.secpod.oval:def:17260
oval:org.secpod.oval:def:700474
oval:org.secpod.oval:def:102464
...

© SecPod Technologies