Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-1709

Опубликовано: 10 июн. 2009
Источник: debian
EPSS Низкий

Описание

Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and unspecified "caches."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
webkitfixed0~svn32442-1package
kdelibsnot-affectedpackage
kde4libsnot-affectedpackage
kdegraphicsfixed4:4.0package

Примечания

  • fixed in upstream commit http://trac.webkit.org/changeset/32230

  • kdegraphics >4.0 not affected since ksvg is only in 3.5.x series)

EPSS

Процентиль: 92%
0.08606
Низкий

Связанные уязвимости

ubuntu
больше 16 лет назад

Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and unspecified "caches."

redhat
больше 16 лет назад

Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and unspecified "caches."

nvd
больше 16 лет назад

Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and unspecified "caches."

github
почти 4 года назад

Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and unspecified "caches."

EPSS

Процентиль: 92%
0.08606
Низкий