Page 277 of 1392 results (0.020 seconds)

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 1

Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks. • http://marc.info/?l=bugtraq&m=110756965213819&w=2 http://securitytracker.com/id?1013087 http://tigger.uic.edu/~jrockw2/safari_20050204.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/19227 •

CVSS: 5.0EPSS: 1%CPEs: 1EXPL: 2

The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks. • http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031459.html http://marc.info/?l=bugtraq&m=110782704923280&w=2 http://www.securityfocus.com/bid/12461 http://www.shmoo.com/idn http://www.shmoo.com/idn/homograph.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/19236 •

CVSS: 7.5EPSS: 1%CPEs: 7EXPL: 0

Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than CVE-2004-1122. • http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html http://secunia.com/advisories/13252 http://secunia.com/multiple_browsers_window_injection_vulnerability_test http://secunia.com/secunia_research/2004-13/advisory https://exchange.xforce.ibmcloud.com/vulnerabilities/18397 •

CVSS: 5.0EPSS: 1%CPEs: 7EXPL: 1

Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays. • http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029458.html http://www.securityfocus.com/bid/11759 https://exchange.xforce.ibmcloud.com/vulnerabilities/18282 •

CVSS: 7.5EPSS: 1%CPEs: 1EXPL: 0

Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the "Dialog Box Spoofing Vulnerability," a different vulnerability than CVE-2004-1314. • http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html http://secunia.com/advisories/12892 http://secunia.com/multiple_browsers_dialog_box_spoofing_test http://secunia.com/secunia_research/2004-10 •