Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2009-1690
HistoryJun 10, 2009 - 2:30 p.m.

CVE-2009-1690

2009-06-1014:30:00
Debian Security Bug Tracker
security-tracker.debian.org
16

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.053 Low

EPSS

Percentile

93.1%

Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by setting an unspecified property of an HTML tag that causes child elements to be freed and later accessed when an HTML error occurs, related to “recursion in certain DOM event handlers.”

OSVersionArchitecturePackageVersionFilename
Debian10allkde4libs< 4:4.3.0-1kde4libs_4:4.3.0-1_all.deb
Debian10allqt4-x11< 4:4.5.2-1qt4-x11_4:4.5.2-1_all.deb

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

0.053 Low

EPSS

Percentile

93.1%