Vulnerabilities > Apple > Safari > 4.0.4

DATE CVE VULNERABILITY TITLE RISK
2010-03-15 CVE-2010-0045 Improper Input Validation vulnerability in Apple Safari
Apple Safari before 4.0.5 on Windows does not properly validate external URL schemes, which allows remote attackers to open local files and execute arbitrary code via a crafted HTML document.
network
apple microsoft CWE-20
critical
9.3
2010-03-15 CVE-2010-0044 Configuration vulnerability in Apple Safari
PubSub in Apple Safari before 4.0.5 does not properly implement use of the Accept Cookies preference to block cookies, which makes it easier for remote web servers to track users by setting a cookie in a (1) RSS or (2) Atom feed.
network
apple CWE-16
4.3
2010-03-15 CVE-2010-0043 Code Injection vulnerability in Apple Safari
ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image.
network
apple microsoft CWE-94
critical
9.3
2010-03-15 CVE-2010-0042 Information Exposure vulnerability in Apple Safari
ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF image.
4.3
2010-03-15 CVE-2010-0041 Information Exposure vulnerability in Apple Safari
ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.
4.3
2010-03-15 CVE-2010-0040 Numeric Errors vulnerability in Apple Safari
Integer overflow in ColorSync in Apple Safari before 4.0.5 on Windows, and iTunes before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with a crafted color profile that triggers a heap-based buffer overflow.
network
apple microsoft CWE-189
critical
9.3
2010-03-03 CVE-2010-0925 Denial-Of-Service vulnerability in Apple Safari 4.0.4
cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in the SRC attribute of a (1) IMG or (2) IFRAME element.
network
low complexity
apple microsoft
5.0
2010-03-03 CVE-2010-0924 Remote Denial Of Service vulnerability in Apple Safari 'background' attribute
cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.3 and 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in the BACKGROUND attribute of a BODY element.
network
low complexity
apple microsoft
5.0
2010-02-18 CVE-2010-0651 Information Exposure vulnerability in multiple products
WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.
network
apple google CWE-200
4.3
2009-08-11 CVE-2009-2416 Use After Free vulnerability in multiple products
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
6.5