CVE-2009-0945
published 2009-05-13CVE-2009-0945: Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
9.32%
94.8th percentile
Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4) SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object, which triggers memory corruption.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 3.2.2 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Qt vulnerabilities
vendor_ubuntu·2009-11-10·CVSS 9.3
CVE-2009-1699 [CRITICAL] Qt vulnerabilities
Title: Qt vulnerabilities
Summary: Qt vulnerabilities
It was discovered that QtWebKit did not properly handle certain SVGPathList
data structures. If a user were tricked into viewing a malicious website,
an attacker could exploit this to execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0945)
Several flaws were discovered in the QtWebKit browser and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-1687,
CVE-2009-1690, CVE-2009-1698, CVE-2009-1711, CVE-2009-1725)
It was discovered that QtWebKit did not properly handle certain XSL
stylesheets. If a user were tricked into viewin
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2009-09-23·CVSS 9.3
CVE-2009-0945 [CRITICAL] WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: WebKit vulnerabilities
It was discovered that WebKit did not properly handle certain SVGPathList
data structures. If a user were tricked into viewing a malicious website,
an attacker could exploit this to execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0945)
Several flaws were discovered in the WebKit browser and JavaScript engines.
If a user were tricked into viewing a malicious website, a remote attacker
could cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-1687, CVE-2009-1690,
CVE-2009-1698, CVE-2009-1711, CVE-2009-1725)
It was discovered that WebKit did not prevent the loading of local Java
applets. If a user were tricked into vi
Ubuntu
KDE-Graphics vulnerabilities
vendor_ubuntu·2009-08-24
CVE-2009-0945 KDE-Graphics vulnerabilities
Title: KDE-Graphics vulnerabilities
Summary: KDE-Graphics vulnerabilities
It was discovered that KDE-Graphics did not properly handle certain
malformed SVG images. If a user were tricked into opening a specially
crafted SVG image, an attacker could cause a denial of service or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Instructions: After a standard system upgrade you need to restart your session to effect
the necessary changes.
Ubuntu
KDE-Libs vulnerabilities
vendor_ubuntu·2009-08-24·CVSS 9.3
CVE-2009-0945 [CRITICAL] KDE-Libs vulnerabilities
Title: KDE-Libs vulnerabilities
Summary: KDE-Libs vulnerabilities
It was discovered that KDE-Libs did not properly handle certain malformed
SVG images. If a user were tricked into opening a specially crafted SVG
image, an attacker could cause a denial of service or possibly execute
arbitrary code with the privileges of the user invoking the program. This
issue only affected Ubuntu 9.04. (CVE-2009-0945)
It was discovered that the KDE JavaScript garbage collector did not
properly handle memory allocation failures. If a user were tricked into
viewing a malicious website, an attacker could cause a denial of service or
possibly execute arbitrary code with the privileges of the user invoking
the program. (CVE-2009-1687)
It was discovered that KDE-Libs did not properly handle HTML content in
Red Hat
kdegraphics: KSVG NULL-pointer dereference in the SVGList interface implementation (ACE)
vendor_redhat·2009-06-25·CVSS 9.3
CVE-2009-0945 [CRITICAL] CWE-476 kdegraphics: KSVG NULL-pointer dereference in the SVGList interface implementation (ACE)
kdegraphics: KSVG NULL-pointer dereference in the SVGList interface implementation (ACE)
Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4) SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object, which triggers memory corruption.
GHSA
GHSA-8rhj-8gqw-pxm4: Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3
ghsa_unreviewed·2022-05-02
CVE-2009-0945 [HIGH] CWE-94 GHSA-8rhj-8gqw-pxm4: Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3
Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4) SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object, which triggers memory corruption.
OSV
CVE-2009-0945: Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3
osv·2009-05-13·CVSS 9.3
CVE-2009-0945 [CRITICAL] CVE-2009-0945: Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3
Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4) SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object, which triggers memory corruption.
No detection rules found.
No public exploits indexed.
http://code.google.com/p/chromium/issues/detail?id=9019http://googlechromereleases.blogspot.com/2009/05/stable-update-bug-fix.htmlhttp://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/35056http://secunia.com/advisories/35074http://secunia.com/advisories/35095http://secunia.com/advisories/35576http://secunia.com/advisories/35805http://secunia.com/advisories/36062http://secunia.com/advisories/36461http://secunia.com/advisories/36790http://secunia.com/advisories/37746http://secunia.com/advisories/43068http://support.apple.com/kb/HT3549http://support.apple.com/kb/HT3550http://support.apple.com/kb/HT3639http://www.debian.org/security/2009/dsa-1950http://www.redhat.com/support/errata/RHSA-2009-1130.htmlhttp://www.securityfocus.com/archive/1/503594/100/0/threadedhttp://www.securityfocus.com/bid/34924http://www.securitytracker.com/id?1022207http://www.ubuntu.com/usn/USN-822-1http://www.ubuntu.com/usn/USN-836-1http://www.ubuntu.com/usn/USN-857-1http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1298http://www.vupen.com/english/advisories/2009/1321http://www.vupen.com/english/advisories/2009/1621http://www.vupen.com/english/advisories/2011/0212http://www.zerodayinitiative.com/advisories/ZDI-09-022https://exchange.xforce.ibmcloud.com/vulnerabilities/50477https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11584https://usn.ubuntu.com/823-1/https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00303.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01177.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01196.htmlhttp://code.google.com/p/chromium/issues/detail?id=9019http://googlechromereleases.blogspot.com/2009/05/stable-update-bug-fix.htmlhttp://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2009/May/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/35056http://secunia.com/advisories/35074http://secunia.com/advisories/35095http://secunia.com/advisories/35576http://secunia.com/advisories/35805http://secunia.com/advisories/36062http://secunia.com/advisories/36461http://secunia.com/advisories/36790http://secunia.com/advisories/37746http://secunia.com/advisories/43068http://support.apple.com/kb/HT3549http://support.apple.com/kb/HT3550http://support.apple.com/kb/HT3639http://www.debian.org/security/2009/dsa-1950http://www.redhat.com/support/errata/RHSA-2009-1130.htmlhttp://www.securityfocus.com/archive/1/503594/100/0/threadedhttp://www.securityfocus.com/bid/34924http://www.securitytracker.com/id?1022207http://www.ubuntu.com/usn/USN-822-1http://www.ubuntu.com/usn/USN-836-1http://www.ubuntu.com/usn/USN-857-1http://www.us-cert.gov/cas/techalerts/TA09-133A.htmlhttp://www.vupen.com/english/advisories/2009/1297http://www.vupen.com/english/advisories/2009/1298http://www.vupen.com/english/advisories/2009/1321http://www.vupen.com/english/advisories/2009/1621http://www.vupen.com/english/advisories/2011/0212http://www.zerodayinitiative.com/advisories/ZDI-09-022https://exchange.xforce.ibmcloud.com/vulnerabilities/50477https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11584https://usn.ubuntu.com/823-1/https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00303.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01177.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01196.html
2009-05-13
Published