263861
|
- |
|
apple
|
safari
|
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML by using the window.open function to change the…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1006
|
2017-08-8 10:29 |
2008-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263862
|
- |
|
apple
|
safari
|
WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1007
|
2017-08-8 10:29 |
2008-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263863
|
- |
|
apple
|
safari
|
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via the document.domain property.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1008
|
2017-08-8 10:29 |
2008-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263864
|
- |
|
apple
|
safari
|
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary JavaScript by modifying the history object.
|
CWE-79
Cross-site Scripting
|
CVE-2008-1009
|
2017-08-8 10:29 |
2008-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263865
|
- |
|
apple
|
safari
|
Buffer overflow in WebKit, as used in Apple Safari before 3.1, allows remote attackers to execute arbitrary code via crafted regular expressions in JavaScript.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-1010
|
2017-08-8 10:29 |
2008-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263866
|
- |
|
apple
|
safari
|
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via a frame that calls a method instance in anot…
|
CWE-79
Cross-site Scripting
|
CVE-2008-1011
|
2017-08-8 10:29 |
2008-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263867
|
- |
|
apple
|
apple_airport_extreme_base_station
|
Unspecified vulnerability in Apple AirPort Extreme Base Station Firmware 7.3.1 allows remote attackers to cause a denial of service (file sharing hang) via a crafted AFP request, related to "input va…
|
CWE-20
Improper Input Validation
|
CVE-2008-1012
|
2017-08-8 10:29 |
2008-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263868
|
- |
|
apple
|
quicktime
|
Apple QuickTime before 7.4.5 enables deserialization of QTJava objects by untrusted Java applets, which allows remote attackers to execute arbitrary code via a crafted applet.
|
NVD-CWE-Other
|
CVE-2008-1013
|
2017-08-8 10:29 |
2008-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263869
|
- |
|
apple
|
quicktime
|
Apple QuickTime before 7.4.5 does not properly handle external URLs in movies, which allows remote attackers to obtain sensitive information.
|
CWE-200 CWE-20
Information Exposure Improper Input Validation
|
CVE-2008-1014
|
2017-08-8 10:29 |
2008-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
263870
|
- |
|
apple
|
quicktime
|
Buffer overflow in the data reference atom handling in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted movie.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-1015
|
2017-08-8 10:29 |
2008-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|