Page 139 of 693 results (0.006 seconds)

CVSS: 9.3EPSS: 92%CPEs: 24EXPL: 2

WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to non-standard NaN representation. WebKit en Apple Safari v4.x anteriores a v4.1.2 y v5.x anteriores a v5.0.2 no valida de forma adecuada los datos con punto flotante, lo que permite a atacantes remotos ejecutar código o provocar una denegación de servicio (caída de la aplicación) a través de un documento HTML manipulado. • https://www.exploit-db.com/exploits/15423 https://www.exploit-db.com/exploits/15548 http://lists.apple.com/archives/security-announce/2010//Nov/msg00003.html http://lists.apple.com/archives/security-announce/2010//Sep/msg00001.html http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html http://secunia.com/advisories/41856 http://secunia.com/advisories/42314 http://secunia.com/advisories/43068 http://secunia.com/advisories/43086 http://support.apple.com/kb&# • CWE-20: Improper Input Validation •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

An unspecified function in the Dalvik API in Android 1.5 and earlier allows remote attackers to cause a denial of service (system process restart) via a crafted application, possibly a related issue to CVE-2009-2656. Una función sin especificar en la API de Dalvik en Android v1.5 y anteriores permite a atacantes remotos producir una denegación de servicio (reinicio de sistema) a través de una aplicación manipulada posiblemente un tema relacionado con CVE-2009-2656. • http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=cf4550c3198d6b3d92cdc52707fe70d7cc0caa9f http://securitytracker.com/id?1022986 http://www.ocert.org/advisories/ocert-2009-014.html http://www.securityfocus.com/archive/1/506948/100/0/threaded http://www.securityfocus.com/bid/36590 https://exchange.xforce.ibmcloud.com/vulnerabilities/53654 •

CVSS: 5.0EPSS: 0%CPEs: 3EXPL: 1

Unspecified vulnerability in the com.android.phone process in Android 1.0, 1.1, and 1.5 allows remote attackers to cause a denial of service (network disconnection) via a crafted SMS message, as demonstrated by Collin Mulliner and Charlie Miller at Black Hat USA 2009. Vulnerabilidad sin especificar en el proceso com.android.phone en Android v1.0, v1.1 y v1.5, permite a atacantes remotos provocar una denegación de servicio (desconexión de la red) a través de un mensaje SMS manipulado, como se demostró por Collini Mulliner y Charlie Miller en la BlackHat USA 2009. • http://osvdb.org/56750 http://www.blackhat.com/presentations/bh-usa-09/MILLER/BHUSA09-Miller-FuzzingPhone-PAPER.pdf http://www.securityfocus.com/bid/35886 •