There are 44 matching records.
Displaying matches 1 through 20.
Search Parameters:
- Keyword (text search): webkit iphone
-
CVE-2011-1344
-
Summary: Use-after-free vulnerability in WebKit, as used in Apple Safari before 5.0.5; iOS before 4.3.2 for iPhone, iPod, and iPad; iOS before 4.2.7 for iPhone 4 (CDMA); and possibly other products allows remote attackers to execute arbitrary code by adding children to a WBR tag and then removing the tag, related to text nodes, as demonstrated by Chaouki Bekrar during a Pwn2Own competition at CanSecWest 2011.
Published: 3/10/2011 3:55:01 PM
CVSS Severity:
v2 - 6.8 MEDIUM
-
CVE-2010-1815
-
Summary: Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving scrollbars.
Published: 9/9/2010 6:00:01 PM
CVSS Severity:
v2 - 6.8 MEDIUM
-
CVE-2010-1814
-
Summary: WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving form menus.
Published: 9/9/2010 6:00:01 PM
CVSS Severity:
v2 - 6.8 MEDIUM
-
CVE-2010-1813
-
Summary: WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving HTML object outlines.
Published: 9/9/2010 6:00:01 PM
CVSS Severity:
v2 - 6.8 MEDIUM
-
CVE-2010-1812
-
Summary: Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving selections.
Published: 9/9/2010 6:00:01 PM
CVSS Severity:
v2 - 6.8 MEDIUM
-
CVE-2010-1781
-
Summary: Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rendering of an inline element.
Published: 9/9/2010 6:00:01 PM
CVSS Severity:
v2 - 6.8 MEDIUM
-
CVE-2010-1757
-
Summary: WebKit in Apple iOS before 4 on the iPhone and iPod touch does not enforce the expected boundary restrictions on content display by an IFRAME element, which allows remote attackers to spoof the user interface via a crafted HTML document.
Published: 6/22/2010 4:30:01 PM
CVSS Severity:
v2 - 6.4 MEDIUM
-
CVE-2010-1407
-
Summary: WebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the history.replaceState method in certain situations involving IFRAME elements, which allows remote attackers to obtain sensitive information via a crafted HTML document.
Published: 6/22/2010 4:30:01 PM
CVSS Severity:
v2 - 4.3 MEDIUM
-
CVE-2010-1769
-
Summary: WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, accesses out-of-bounds memory during the handling of tables, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, a different vulnerability than CVE-2010-1387 and CVE-2010-1763.
Published: 6/18/2010 12:30:01 PM
CVSS Severity:
v2 - 10.0 HIGH
-
CVE-2010-1387
-
Summary: Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.
Published: 6/18/2010 12:30:01 PM
CVSS Severity:
v2 - 9.3 HIGH
-
CVE-2010-1119
-
Summary: Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo and Ralf Philipp Weinmann during a Pwn2Own competition at CanSecWest 2010.
Published: 3/25/2010 5:00:01 PM
CVSS Severity:
v2 - 10.0 HIGH
-
CVE-2010-1029
-
Summary: Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a STYLE element composed of a large number of *> sequences.
Published: 3/19/2010 5:30:00 PM
CVSS Severity:
v2 - 5.0 MEDIUM
-
CVE-2009-2797
-
Summary: The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by reading Referer logs on a web server.
Published: 9/10/2009 5:30:01 PM
CVSS Severity:
v2 - 5.0 MEDIUM
-
CVE-2009-2199
-
Summary: Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified homoglyphs.
Published: 8/12/2009 3:30:00 PM
CVSS Severity:
v2 - 5.8 MEDIUM
-
CVE-2009-1725
-
Summary: WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
Published: 7/9/2009 1:30:00 PM
CVSS Severity:
v2 - 9.3 HIGH
-
CVE-2009-1724
-
Summary: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors related to parent and top objects.
Published: 7/9/2009 1:30:00 PM
CVSS Severity:
v2 - 4.3 MEDIUM
-
CVE-2009-1692
-
Summary: WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows remote attackers to cause a denial of service (memory consumption or device reset) via a web page containing an HTMLSelectElement object with a large length attribute, related to the length property of a Select object.
Published: 6/19/2009 12:30:00 PM
CVSS Severity:
v2 - 7.1 HIGH
-
CVE-2009-1702
-
Summary: Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to improper handling of Location and History objects.
Published: 6/10/2009 2:00:00 PM
CVSS Severity:
v2 - 4.3 MEDIUM
-
CVE-2009-1701
-
Summary: Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by destroying a document.body element that has an unspecified XML container with elements that support the dir attribute.
Published: 6/10/2009 2:00:00 PM
CVSS Severity:
v2 - 9.3 HIGH
-
CVE-2009-1700
-
Summary: The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read XML content from arbitrary web pages via a crafted document.
Published: 6/10/2009 2:00:00 PM
CVSS Severity:
v2 - 4.3 MEDIUM