[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-1690Date: (C)2009-06-10   (M)2024-02-22


Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by setting an unspecified property of an HTML tag that causes child elements to be freed and later accessed when an HTML error occurs, related to "recursion in certain DOM event handlers."

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1022345
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=803
BID-35260
SECUNIA-35379
SECUNIA-36057
SECUNIA-36062
SECUNIA-36790
SECUNIA-37746
SECUNIA-43068
OSVDB-54990
ADV-2009-1522
ADV-2009-1621
ADV-2011-0212
APPLE-SA-2009-06-08-1
APPLE-SA-2009-06-17-1
DSA-1950
FEDORA-2009-8020
FEDORA-2009-8039
FEDORA-2009-8046
FEDORA-2009-8049
MDVSA-2009:330
SUSE-SR:2011:002
USN-822-1
USN-836-1
USN-857-1
http://support.apple.com/kb/HT3613
http://support.apple.com/kb/HT3639
oval:org.mitre.oval:def:11009

CPE    41
cpe:/o:apple:iphone_os:1.1.0:-:iphone
cpe:/o:apple:iphone_os:1.0.2:-:iphone
cpe:/o:apple:iphone_os:1.0.0
cpe:/o:apple:iphone_os:1.0.2
...
CWE    1
CWE-399
OVAL    25
oval:org.secpod.oval:def:700364
oval:org.secpod.oval:def:17263
oval:org.secpod.oval:def:700474
oval:org.secpod.oval:def:600390
...

© SecPod Technologies