CVE-2009-1709

Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and unspecified "caches."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
VendorProductVersion
applesafari
𝑥
≤ 4.0_beta
applesafari
0.8
applesafari
0.9
applesafari
1.0
applesafari
1.0.3
applesafari
1.1
applesafari
1.2
applesafari
1.3
applesafari
1.3.1
applesafari
1.3.2
applesafari
2.0
applesafari
2.0.2
applesafari
2.0.4
applesafari
3.0
applesafari
3.0.2
applesafari
3.0.3
applesafari
3.0.4
applesafari
3.1
applesafari
3.1.1
applesafari
3.1.2
applesafari
3.2.1
applesafari
3.2.3
applesafari
𝑥
≤ 3.2.3
applesafari
3.0
applesafari
3.0.1
applesafari
3.0.2
applesafari
3.0.3
applesafari
3.0.4
applesafari
3.1
applesafari
3.1.1
applesafari
3.1.2
applesafari
3.2
applesafari
3.2.1
applesafari
3.2.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kde4libs
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
dapper
dne
kdegraphics
jaunty
not-affected
intrepid
not-affected
hardy
Fixed 4:3.5.10-0ubuntu1~hardy1.1
released
dapper
ignored
qt4-x11
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
dapper
not-affected
webkit
jaunty
not-affected
intrepid
not-affected
hardy
not-affected
dapper
dne
Common Weakness Enumeration
References