4.3
CVSSv2

CVE-2009-2419

Published: 09/07/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote malicious users to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML document that references a zero-length .js file and the JavaScript reload function. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 4.0

apple safari 4.0.1

Exploits

source: wwwsecurityfocuscom/bid/35555/info Apple Safari is prone to a denial-of-service vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this issue to crash the affected application, denying service to legitimate users Given the nature of this issue, the attacker may also be able to run ar ...