Vulnerabilities > Apple > Medium

DATE CVE VULNERABILITY TITLE RISK
2009-06-10 CVE-2009-1696 Cryptographic Issues vulnerability in Apple Safari
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 uses predictable random numbers in JavaScript applications, which makes it easier for remote web servers to track the behavior of a Safari user during a session.
network
low complexity
apple CWE-310
5.0
2009-06-10 CVE-2009-1695 Cross-Site Scripting vulnerability in Apple Safari
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving access to frame contents after completion of a page transition.
network
apple CWE-79
4.3
2009-06-10 CVE-2009-1694 Multiple Security vulnerability in RETIRED: Apple Safari Prior to 4.0
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read images from arbitrary web sites via vectors involving a CANVAS element and redirection, related to a "cross-site image capture issue."
network
apple
5.8
2009-06-10 CVE-2009-1693 Multiple Security vulnerability in RETIRED: Apple Safari Prior to 4.0
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to read images from arbitrary web sites via a CANVAS element with an SVG image, related to a "cross-site image capture issue."
network
apple
5.8
2009-06-10 CVE-2009-1691 Cross-Site Scripting vulnerability in Apple Safari
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to insufficient access control for standard JavaScript prototypes in other domains.
network
apple CWE-79
4.3
2009-06-10 CVE-2009-1689 Cross-Site Scripting vulnerability in Apple Safari
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving submission of a form to the about:blank URL, leading to security-context replacement.
network
apple CWE-79
4.3
2009-06-10 CVE-2009-1688 Cross-Site Scripting vulnerability in Apple Safari
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to determining a security context through an approach that is not the "HTML 5 standard method."
network
apple CWE-79
4.3
2009-06-10 CVE-2009-1685 Cross-Site Scripting vulnerability in Apple Safari
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML by overwriting the document.implementation property of (1) an embedded document or (2) a parent document.
network
apple CWE-79
4.3
2009-06-10 CVE-2009-1684 Cross-Site Scripting vulnerability in Apple Safari
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via an event handler that triggers script execution in the context of the next loaded document.
network
apple CWE-79
4.3
2009-06-10 CVE-2009-1682 Credentials Management vulnerability in Apple Safari
Apple Safari before 4.0 does not properly check for revoked Extended Validation (EV) certificates, which makes it easier for remote attackers to trick a user into accepting an invalid certificate.
network
apple CWE-255
4.3