Lucene search

K
cveMitreCVE-2009-1698
HistoryJun 10, 2009 - 6:00 p.m.

CVE-2009-1698

2009-06-1018:00:00
CWE-94
mitre
web.nvd.nist.gov
50
cve-2009-1698
webkit
apple safari
iphone os
ipod touch
css
memory corruption
application crash
remote code execution

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

High

EPSS

0.036

Percentile

91.8%

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.

Affected configurations

Nvd
Node
applesafariRange3.2.2
OR
applesafariMatch2.0
OR
applesafariMatch2.0.0
OR
applesafariMatch2.0.1
OR
applesafariMatch2.0.2
OR
applesafariMatch2.0.3
OR
applesafariMatch2.0.3417.8
OR
applesafariMatch2.0.3417.9
OR
applesafariMatch2.0.3417.9.2
OR
applesafariMatch2.0.3417.9.3
OR
applesafariMatch2.0.4
OR
applesafariMatch3.0
OR
applesafariMatch3.0.0
OR
applesafariMatch3.0.0b
OR
applesafariMatch3.0.1
OR
applesafariMatch3.0.1beta
OR
applesafariMatch3.0.1b
OR
applesafariMatch3.0.2
OR
applesafariMatch3.0.2b
OR
applesafariMatch3.0.3
OR
applesafariMatch3.0.3b
OR
applesafariMatch3.0.4
OR
applesafariMatch3.0.4b
OR
applesafariMatch3.1.0
OR
applesafariMatch3.1.0b
OR
applesafariMatch3.1.1
OR
applesafariMatch3.1.2
OR
applesafariMatch3.2.0
OR
applesafariMatch3.2.1
Node
appleiphone_osMatch1.0.0
OR
appleiphone_osMatch1.0.1
OR
appleiphone_osMatch1.0.2
OR
appleiphone_osMatch1.1.0
OR
appleiphone_osMatch1.1.1
OR
appleiphone_osMatch1.1.2
OR
appleiphone_osMatch1.1.3
OR
appleiphone_osMatch1.1.4
OR
appleiphone_osMatch1.1.5
OR
appleiphone_osMatch2.0
OR
appleiphone_osMatch2.0.0
OR
appleiphone_osMatch2.0.1
OR
appleiphone_osMatch2.0.2
OR
appleiphone_osMatch2.1
OR
appleiphone_osMatch2.1.1
OR
appleiphone_osMatch2.2
OR
appleiphone_osMatch2.2.1
AND
appleiphone_os
Node
appleiphone_osMatch1.1.0
OR
appleiphone_osMatch1.1.1
OR
appleiphone_osMatch1.1.2
OR
appleiphone_osMatch1.1.3
OR
appleiphone_osMatch1.1.4
OR
appleiphone_osMatch1.1.5
OR
appleiphone_osMatch2.0
OR
appleiphone_osMatch2.0.0
OR
appleiphone_osMatch2.0.1
OR
appleiphone_osMatch2.0.2
OR
appleiphone_osMatch2.1
OR
appleiphone_osMatch2.1.1
OR
appleiphone_osMatch2.2
OR
appleiphone_osMatch2.2.1
AND
appleipod_touch
VendorProductVersionCPE
applesafari*cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
applesafari2.0cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:*
applesafari2.0.0cpe:2.3:a:apple:safari:2.0.0:*:*:*:*:*:*:*
applesafari2.0.1cpe:2.3:a:apple:safari:2.0.1:*:*:*:*:*:*:*
applesafari2.0.2cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:*
applesafari2.0.3cpe:2.3:a:apple:safari:2.0.3:*:*:*:*:*:*:*
applesafari2.0.3cpe:2.3:a:apple:safari:2.0.3:417.8:*:*:*:*:*:*
applesafari2.0.3cpe:2.3:a:apple:safari:2.0.3:417.9:*:*:*:*:*:*
applesafari2.0.3cpe:2.3:a:apple:safari:2.0.3:417.9.2:*:*:*:*:*:*
applesafari2.0.3cpe:2.3:a:apple:safari:2.0.3:417.9.3:*:*:*:*:*:*
Rows per page:
1-10 of 481

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

High

EPSS

0.036

Percentile

91.8%