CVE-2005-4504 – Apple Mac OSX - KHTMLParser Remote Denial of Service
https://notcve.org/view.php?id=CVE-2005-4504
22 Dec 2005 — The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a large ROWSPAN attribute in a TD tag. • https://www.exploit-db.com/exploits/26971 •
CVE-2005-3897
https://notcve.org/view.php?id=CVE-2005-3897
29 Nov 2005 — Apple Safari 2.0.2 allows remote attackers to cause a denial of service (system slowdown) via a Javascript BODY onload event that calls the window function. • http://marc.info/?l=bugtraq&m=113278010907401&w=2 •
CVE-2005-2524
https://notcve.org/view.php?id=CVE-2005-2524
25 Oct 2005 — Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site. • http://lists.apple.com/archives/security-announce/2005/Sep/msg00002.html •
CVE-2005-3018 – Apple Safari 1.x/2.0.1 - Data URI Memory Corruption
https://notcve.org/view.php?id=CVE-2005-3018
21 Sep 2005 — Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL. • https://www.exploit-db.com/exploits/26271 •
CVE-2005-2594 – Apple Safari 1.3 Web Browser - JavaScript Invalid Address Denial of Service
https://notcve.org/view.php?id=CVE-2005-2594
17 Aug 2005 — Apple Safari 1.3 (132) on Mac OS X 1.3.9 allows remote attackers to cause a denial of service (crash) via certain Javascript, possibly involving a function that defines a handler for itself within the function body. • https://www.exploit-db.com/exploits/26128 •
CVE-2005-2272
https://notcve.org/view.php?id=CVE-2005-2272
13 Jul 2005 — Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability." • http://docs.info.apple.com/article.html?artnum=302847 •
CVE-2005-1385
https://notcve.org/view.php?id=CVE-2005-1385
02 May 2005 — Safari 1.3 allows remote attackers to cause a denial of service (application crash) via a long https URL that triggers a NULL pointer dereference. • http://marc.info/?l=bugtraq&m=111473570624498&w=2 •
CVE-2005-0976
https://notcve.org/view.php?id=CVE-2005-0976
18 Apr 2005 — AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript component, as demonstrated using automatically mounted disk images and file:// URLs. • http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html •
CVE-2005-0341
https://notcve.org/view.php?id=CVE-2005-0341
10 Feb 2005 — Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks. • http://marc.info/?l=bugtraq&m=110756965213819&w=2 •
CVE-2005-0234
https://notcve.org/view.php?id=CVE-2005-0234
07 Feb 2005 — The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks. • http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html •