CVE-2009-1698Code Injection in Apple Safari

CWE-94Code Injection8 documents6 sources
Severity
9.3CRITICALNVD
EPSS
7.8%
top 8.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 10
Latest updateMay 2

Description

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages2 packages

NVDapple/iphone_os17 versions+16
NVDapple/safari3.2.2+23

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g539-5hv9-9m5x: WebKit in Apple Safari before 42022-05-02
OSV
CVE-2009-1698: WebKit in Apple Safari before 42009-06-10

📋Vendor Advisories

4
Ubuntu
Qt vulnerabilities2009-11-10
Ubuntu
WebKit vulnerabilities2009-09-23
Ubuntu
KDE-Libs vulnerabilities2009-08-24
Red Hat
kdelibs: KHTML CSS parser - incorrect handling CSS "style" attribute content (DoS, ACE)2009-06-25

💬Community

1
Bugzilla
CVE-2009-1698 kdelibs: KHTML CSS parser - incorrect handling CSS "style" attribute content (DoS, ACE)2009-06-17