Lucene search

K
cve[email protected]CVE-2009-1690
HistoryJun 10, 2009 - 2:30 p.m.

CVE-2009-1690

2009-06-1014:30:00
CWE-399
web.nvd.nist.gov
43
cve-2009-1690
use-after-free vulnerability
webkit
apple safari
iphone os
ipod touch
google chrome
arbitrary code execution
denial of service
memory corruption
application crash
dom event handlers
html error

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

High

0.053 Low

EPSS

Percentile

93.1%

Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by setting an unspecified property of an HTML tag that causes child elements to be freed and later accessed when an HTML error occurs, related to “recursion in certain DOM event handlers.”

Affected configurations

NVD
Node
applesafariRange4.0_betamac
OR
applesafariMatch0.8mac
OR
applesafariMatch0.9mac
OR
applesafariMatch1.0mac
OR
applesafariMatch1.0.3mac
OR
applesafariMatch1.1mac
OR
applesafariMatch1.2mac
OR
applesafariMatch1.3mac
OR
applesafariMatch1.3.1mac
OR
applesafariMatch1.3.2mac
OR
applesafariMatch2.0mac
OR
applesafariMatch2.0.2mac
OR
applesafariMatch2.0.4mac
OR
applesafariMatch3.0mac
OR
applesafariMatch3.0.2-mac
OR
applesafariMatch3.0.3mac
OR
applesafariMatch3.0.4mac
OR
applesafariMatch3.1mac
OR
applesafariMatch3.1.1mac
OR
applesafariMatch3.1.2mac
OR
applesafariMatch3.2.1mac
OR
applesafariMatch3.2.3mac
Node
applesafariRange3.2.3windows
OR
applesafariMatch3.0windows
OR
applesafariMatch3.0.1windows
OR
applesafariMatch3.0.2windows
OR
applesafariMatch3.0.3windows
OR
applesafariMatch3.0.4windows
OR
applesafariMatch3.1windows
OR
applesafariMatch3.1.1windows
OR
applesafariMatch3.1.2windows
OR
applesafariMatch3.2-windows
OR
applesafariMatch3.2.1windows
OR
applesafariMatch3.2.2windows
Node
appleiphone_osMatch1.0
OR
appleiphone_osMatch1.0.0
OR
appleiphone_osMatch1.0.1
OR
appleiphone_osMatch1.0.1-iphone
OR
appleiphone_osMatch1.0.2
OR
appleiphone_osMatch1.0.2-iphone
OR
appleiphone_osMatch1.1
OR
appleiphone_osMatch1.1.0
OR
appleiphone_osMatch1.1.0-iphone
OR
appleiphone_osMatch1.1.0-ipodtouch
OR
appleiphone_osMatch1.1.1
OR
appleiphone_osMatch1.1.1-iphone
OR
appleiphone_osMatch1.1.2
OR
appleiphone_osMatch1.1.2-iphone
OR
appleiphone_osMatch1.1.2-ipodtouch
OR
appleiphone_osMatch1.1.3
OR
appleiphone_osMatch1.1.3-iphone
OR
appleiphone_osMatch1.1.3-ipodtouch
OR
appleiphone_osMatch1.1.4
OR
appleiphone_osMatch1.1.4-iphone
OR
appleiphone_osMatch1.1.4-ipodtouch
OR
appleiphone_osMatch1.1.5
OR
appleiphone_osMatch1.1.5-iphone
OR
appleiphone_osMatch1.1.5-ipodtouch
OR
appleiphone_osMatch2.0
OR
appleiphone_osMatch2.0.0
OR
appleiphone_osMatch2.0.0-iphone
OR
appleiphone_osMatch2.0.0-ipodtouch
OR
appleiphone_osMatch2.0.1
OR
appleiphone_osMatch2.0.1-iphone
OR
appleiphone_osMatch2.0.1-ipodtouch
OR
appleiphone_osMatch2.0.2
OR
appleiphone_osMatch2.0.2-iphone
OR
appleiphone_osMatch2.0.2-ipodtouch
OR
appleiphone_osMatch2.1
OR
appleiphone_osMatch2.1-iphone
OR
appleiphone_osMatch2.1-ipodtouch
OR
appleiphone_osMatch2.2-iphone
OR
appleiphone_osMatch2.2-ipodtouch
OR
appleiphone_osMatch2.2.1-iphone
OR
appleiphone_osMatch2.2.1-ipodtouch
Node
googlechromeMatch1.0.154.53

References

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

High

0.053 Low

EPSS

Percentile

93.1%