Page 265 of 1351 results (0.009 seconds)

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 2

The AutoFill feature in Apple Safari 2.0.4 does not properly verify that all automatically populated form fields are visible to the user, which allows remote attackers to obtain sensitive information, such as usernames and passwords, via input fields of zero width, a variant of CVE-2006-6077. La caraterística AutoFill de Apple Safari 2.0.4 no verifica de forma adecuada que todos los campos poblados del formulario sean visibles al usuario, lo cual permite a un atacante remoto obtener información sensible, como nombres de usuario y contraseñas, a través de campos de entrada de tamaño zero, una variante de CVE-2006-6077. • http://secunia.com/advisories/23066 http://tearesolutions.com/2006/11/how_to_steal_passwords_from_safaris_autofill.html http://www.securityfocus.com/bid/21329 •

CVSS: 7.5EPSS: 2%CPEs: 10EXPL: 3

WebCore in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted HTML that triggers a "memory management error" in WebKit, possibly due to a buffer overflow, as originally reported for the KHTMLParser::popOneBlock function in Apple Safari 2.0.4 using Javascript that changes document.body.innerHTML within a DIV tag. WebCore en Apple Mac OS X 10.3.9 y 10.4 hasta 10.4.7 permite a atacantes remotos provocar una denegación de servicio (caída) y posiblemente ejecutar código de su elección mediante HTML artesanal que provoca un "error de gestión de memoria" en WebKit, posiblemente debido a un desbordamiento de buffer, como fue originalmente reportado para la función KHTMLParser::popOneBlock en Apple Safari 2.0.4 usando Javascript que cambia document.body.innerHTML dentro de una etiqueta DIV. • http://browserfun.blogspot.com/2006/07/mobb-31-safari-khtmlparserpoponeblock.html http://lists.apple.com/archives/security-announce/2006/Sep/msg00002.html http://secunia.com/advisories/21271 http://secunia.com/advisories/22187 http://securitytracker.com/id?1016957 http://www.osvdb.org/27534 http://www.securityfocus.com/bid/19250 http://www.vupen.com/english/advisories/2006/3069 http://www.vupen.com/english/advisories/2006/3852 https://exchange.xforce.ibmcloud.com/vulnerabilities/28081 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 5.0EPSS: 6%CPEs: 1EXPL: 4

Apple Safari 2.0.4/419.3 allows remote attackers to cause a denial of service (application crash) via a DHTML setAttributeNode function call with zero arguments, which triggers a null dereference. Apple Safari 2.0.4/419.3 permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) mediante una llamada a la función DHTML setAttributeNode sin argumentos, que desemboca en una referencia nula. • https://www.exploit-db.com/exploits/28165 http://browserfun.blogspot.com/2006/07/mobb-5-dhtml-setattributenode.html http://securitytracker.com/id?1016441 http://www.osvdb.org/26838 http://www.securityfocus.com/bid/18822 http://www.vupen.com/english/advisories/2006/2671 https://exchange.xforce.ibmcloud.com/vulnerabilities/27594 •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 0

Apple Safari 2.0.3 (417.9.3) on Mac OS X 10.4.6 allows remote attackers to cause a denial of service (CPU consumption) via Javascript with an infinite for loop. NOTE: it could be argued that this is not a vulnerability, unless it interferes with the operation of the system outside of the scope of Safari itself. Apple Safari v2.0.3 (417.9.3) en Mac OS X v10.4.6 permite a atacantes remotos causar una denegación de servicio (consumo CPU) a través de Javascript con un bucle infinito. NOTA: esto podría ser argumentado como que no es una vulnerabilidad, a menos que interfiera con la operación del sistema fuera del alcance de Safari. • http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/046150.html https://exchange.xforce.ibmcloud.com/vulnerabilities/26558 •

CVSS: 5.0EPSS: 9%CPEs: 2EXPL: 2

Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a TD element with a large number in the rowspan attribute. • https://www.exploit-db.com/exploits/1715 http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045472.html http://secunia.com/advisories/19763 http://securitytracker.com/id?1015982 http://www.securityfocus.com/archive/1/431874/100/0/threaded http://www.securityfocus.com/archive/1/431944/100/0/threaded http://www.securityfocus.com/bid/17674 http://www.vupen.com/english/advisories/2006/1508 https://exchange.xforce.ibmcloud.com/vulnerabilities/25998 •