CVE-2009-1725
published 2009-07-09CVE-2009-1725: WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE…
PriorityP339critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.19%
92.8th percentile
WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 3.0.1 | — |
| apple | iphone_os | <= 3.1 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | safari | <= 4.0.1 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Qt vulnerabilities
vendor_ubuntu·2009-11-10·CVSS 9.3
CVE-2009-1699 [CRITICAL] Qt vulnerabilities
Title: Qt vulnerabilities
Summary: Qt vulnerabilities
It was discovered that QtWebKit did not properly handle certain SVGPathList
data structures. If a user were tricked into viewing a malicious website,
an attacker could exploit this to execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0945)
Several flaws were discovered in the QtWebKit browser and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-1687,
CVE-2009-1690, CVE-2009-1698, CVE-2009-1711, CVE-2009-1725)
It was discovered that QtWebKit did not properly handle certain XSL
stylesheets. If a user were tricked into viewin
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2009-09-23·CVSS 9.3
CVE-2009-0945 [CRITICAL] WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: WebKit vulnerabilities
It was discovered that WebKit did not properly handle certain SVGPathList
data structures. If a user were tricked into viewing a malicious website,
an attacker could exploit this to execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0945)
Several flaws were discovered in the WebKit browser and JavaScript engines.
If a user were tricked into viewing a malicious website, a remote attacker
could cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-1687, CVE-2009-1690,
CVE-2009-1698, CVE-2009-1711, CVE-2009-1725)
It was discovered that WebKit did not prevent the loading of local Java
applets. If a user were tricked into vi
Red Hat
qt-4.5.2: improper handling of numeric character references (ACE, DoS)
vendor_redhat·2009-07-25·CVSS 9.3
CVE-2009-1725 [CRITICAL] qt-4.5.2: improper handling of numeric character references (ACE, DoS)
qt-4.5.2: improper handling of numeric character references (ACE, DoS)
WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
Statement: Not vulnerable. This issue did not affect the versions of the kdelibs packages, as shipped with Red Hat Enterprise Linux 3, 4, or 5.
GHSA
GHSA-6h8h-64g5-rgv5: WebKit in Apple Safari before 4
ghsa_unreviewed·2022-05-02
CVE-2009-1725 [HIGH] GHSA-6h8h-64g5-rgv5: WebKit in Apple Safari before 4
WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
OSV
CVE-2009-1725: WebKit in Apple Safari before 4
osv·2009-07-09·CVSS 9.3
CVE-2009-1725 [CRITICAL] CVE-2009-1725: WebKit in Apple Safari before 4
WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2009/Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Sep/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://osvdb.org/55739http://secunia.com/advisories/35758http://secunia.com/advisories/36057http://secunia.com/advisories/36062http://secunia.com/advisories/36347http://secunia.com/advisories/36677http://secunia.com/advisories/36790http://secunia.com/advisories/37746http://secunia.com/advisories/43068http://support.apple.com/kb/HT3666http://support.apple.com/kb/HT3860http://websvn.kde.org/?view=rev&revision=1002162http://websvn.kde.org/?view=rev&revision=1002163http://websvn.kde.org/?view=rev&revision=1002164http://www.debian.org/security/2009/dsa-1950http://www.mandriva.com/security/advisories?name=MDVSA-2009:330http://www.securityfocus.com/bid/35607http://www.securitytracker.com/id?1022526http://www.ubuntu.com/usn/USN-836-1http://www.ubuntu.com/usn/USN-857-1http://www.vupen.com/english/advisories/2009/1827http://www.vupen.com/english/advisories/2011/0212https://bugzilla.redhat.com/show_bug.cgi?id=513813https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5777https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00931.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00933.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01177.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01196.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01199.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01200.htmlhttp://lists.apple.com/archives/security-announce/2009/Jul/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2009/Sep/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://osvdb.org/55739http://secunia.com/advisories/35758http://secunia.com/advisories/36057http://secunia.com/advisories/36062http://secunia.com/advisories/36347http://secunia.com/advisories/36677http://secunia.com/advisories/36790http://secunia.com/advisories/37746http://secunia.com/advisories/43068http://support.apple.com/kb/HT3666http://support.apple.com/kb/HT3860http://websvn.kde.org/?view=rev&revision=1002162http://websvn.kde.org/?view=rev&revision=1002163http://websvn.kde.org/?view=rev&revision=1002164http://www.debian.org/security/2009/dsa-1950http://www.mandriva.com/security/advisories?name=MDVSA-2009:330http://www.securityfocus.com/bid/35607http://www.securitytracker.com/id?1022526http://www.ubuntu.com/usn/USN-836-1http://www.ubuntu.com/usn/USN-857-1http://www.vupen.com/english/advisories/2009/1827http://www.vupen.com/english/advisories/2011/0212https://bugzilla.redhat.com/show_bug.cgi?id=513813https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5777https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00931.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00933.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01177.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01196.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01199.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg01200.html
2009-07-09
Published