Search CVE reports


Toggle filters

1531 – 1540 of 1547 results


CVE-2009-1713

Medium priority

Some fixes available 1 of 2

The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via...

2 affected packages

qt4-x11, webkit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt4-x11
webkit
Show less packages

CVE-2009-1712

Medium priority

Some fixes available 4 of 5

WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element.

2 affected packages

qt4-x11, webkit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt4-x11
webkit
Show less packages

CVE-2009-1711

Medium priority

Some fixes available 3 of 4

WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.

2 affected packages

qt4-x11, webkit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt4-x11
webkit
Show less packages

CVE-2009-1699

Medium priority

Some fixes available 1 of 2

The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to...

2 affected packages

qt4-x11, webkit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt4-x11
webkit
Show less packages

CVE-2009-1698

Medium priority

Some fixes available 13 of 16

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a...

4 affected packages

kde4libs, kdelibs, qt4-x11, webkit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kde4libs
kdelibs
qt4-x11
webkit
Show less packages

CVE-2009-1690

Medium priority

Some fixes available 13 of 16

Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to...

4 affected packages

kde4libs, kdelibs, qt4-x11, webkit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kde4libs
kdelibs
qt4-x11
webkit
Show less packages

CVE-2009-1687

Medium priority

Some fixes available 13 of 16

The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle allocation failures, which allows remote attackers to...

4 affected packages

kde4libs, kdelibs, qt4-x11, webkit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kde4libs
kdelibs
qt4-x11
webkit
Show less packages

CVE-2009-0945

Medium priority

Some fixes available 6 of 8

Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65,...

5 affected packages

kde4libs, kdegraphics, kdelibs, qt4-x11, webkit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kde4libs
kdegraphics
kdelibs
qt4-x11
webkit
Show less packages

CVE-2009-1598

Low priority
Not affected

Google Chrome executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat...

1 affected package

webkit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
webkit
Show less packages

CVE-2008-6059

Low priority
Ignored

xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain...

1 affected package

webkit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
webkit
Show less packages