HIGH
WebKit: buffer overflow in floating point numbers parsing
Published Aug 12, 2009
9.3
HIGHCVSS 2.0
EPSS 13.29%
Description
Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted floating-point numbers.
Affected products
No data.
AND
Running on/with
OR
- 10.4.
- 10.5.7
- 10.5.8
- 10.4.11
- 10.5.7
- 10.5.8
- n/a
- n/a
OR
- ≤ 4.0.2
- 0.8
- 0.9
- 1.0
- 1.0
- 1.0
- 1.0.0
- 1.0.0b1
- 1.0.0b2
- 1.0.1
- 1.0.2
- 1.0.3
- 1.0.3
- 1.0.3
- 1.1
- 1.1.0
- 1.1.1
- 1.2
- 1.2.0
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2.5
- 1.3
- 1.3.0
- 1.3.1
- 1.3.2
- 1.3.2
- 1.3.2
- 2.0
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.3
- 2.0.3
- 2.0.3
- 2.0.3
- 2.0.3_417.9.3
- 2.0.4
- 2.0.4_419.3
- 2.0_pre
- 3
- 3.0
- 3.0.0
- 3.0.0b
- 3.0.1
- 3.0.1
- 3.0.1b
- 3.0.2
- 3.0.2b
- 3.0.3
- 3.0.3
- 3.0.3b
- 3.0.4
- 3.0.4_beta
- 3.0.4b
- 3.1
- 3.1.0
- 3.1.0b
- 3.1.1
- 3.1.2
- 3.2
- 3.2.0
- 3.2.1
- 3.2.2
- 4.0
- 4.0
- 4.0.1
- 4.0_beta
- 4beta
- beta2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (14)
- http://lists.apple.com/archives/security-announce/2009/Aug/msg00002.html vendor-advisoryx_refsource_APPLEPatchVendor Advisory
- http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/43068 third-party-advisoryx_refsource_SECUNIA
- http://support.apple.com/kb/HT3733 x_refsource_CONFIRMPatchVendor Advisory
- http://support.apple.com/kb/HT4225 x_refsource_CONFIRM
- http://www.securityfocus.com/bid/36023 vdb-entryx_refsource_BIDPatch
- http://www.securitytracker.com/id?1022717 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2011/0212 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-2195 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=517273 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-2191 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-2195
- https://www.cve.org/CVERecord?id=CVE-2009-2195
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 12, 2009
Updated Aug 7, 2024
Reserved Jun 24, 2009
Link CVE-2009-2195
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-2191 Assigner mitre
Published Aug 12, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-2191