Vulnerabilities > Apple > Ipod Touch > Critical

DATE CVE VULNERABILITY TITLE RISK
2009-07-09 CVE-2009-1725 Numeric Errors vulnerability in Apple Safari
WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
network
apple CWE-189
critical
9.3
2009-06-10 CVE-2009-1698 Code Injection vulnerability in Apple Safari
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
network
apple CWE-94
critical
9.3
2009-06-10 CVE-2009-1701 Resource Management Errors vulnerability in Apple Safari
Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by destroying a document.body element that has an unspecified XML container with elements that support the dir attribute.
network
apple CWE-399
critical
9.3
2008-09-11 CVE-2008-3632 Resource Management Errors vulnerability in Apple Iphone, Iphone OS and Ipod Touch
Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a web page with crafted Cascading Style Sheets (CSS) import statements.
network
apple CWE-399
critical
9.3