6.8
CVSSv2

CVE-2009-2804

Published: 14/09/2009 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari prior to 4.0.4 on Windows, allows remote malicious users to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an image, leading to a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.4.11

apple mac os x server 10.4.11

apple mac os x 10.5.8

apple mac os x server 10.5.8

apple safari 1.1.0

apple safari 1.0

apple safari 1.0.0

apple safari 1.3.1

apple safari 1.3.0

apple safari 1.2

apple safari 3.0.1

apple safari 2.0.4

apple safari 2.0.3_417.9.3

apple safari 2.0.1

apple safari 3.0.4b

apple safari 3.1

apple safari 3.2.1

apple safari 3.2.2

apple safari

apple safari 1.0.3

apple safari 0.9

apple safari 0.8

apple safari 1.3

apple safari 1.2.5

apple safari 3.0.0b

apple safari 3.0.0

apple safari 2.0.3

apple safari 3.0.4_beta

apple safari 3.0.4

apple safari 3.1.0

apple safari 3.1.0b

apple safari 3.2.3

apple safari 4.0

apple safari 1.0.2

apple safari 1.0.1

apple safari 2.0.0

apple safari 2.0

apple safari 1.2.4

apple safari 1.2.3

apple safari 3.0

apple safari 3

apple safari 3.0.3b

apple safari 3.0.3

apple safari 3.0.2b

apple safari 3.1.1

apple safari 3.1.2

apple safari 4.0.0b

apple safari 4.0.1

apple safari 1.1.1

apple safari 1.0.0b2

apple safari 1.0.0b1

apple safari 2

apple safari 1.3.2

apple safari 1.2.2

apple safari 1.2.1

apple safari 1.2.0

apple safari 2.0_pre

apple safari 2.0.4_419.3

apple safari 2.0.2

apple safari 3.0.2

apple safari 3.0.1b

apple safari 3.2

apple safari 3.2.0

apple safari 4.0.2