CVE Vulnerabilities

CVE-2009-1709

Published: Jun 10, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and unspecified caches.

Affected Software

NameVendorStart VersionEnd Version
SafariApple*4.0_beta (including)
SafariApple0.8 (including)0.8 (including)
SafariApple0.9 (including)0.9 (including)
SafariApple1.0 (including)1.0 (including)
SafariApple1.0.3 (including)1.0.3 (including)
SafariApple1.1 (including)1.1 (including)
SafariApple1.2 (including)1.2 (including)
SafariApple1.3 (including)1.3 (including)
SafariApple1.3.1 (including)1.3.1 (including)
SafariApple1.3.2 (including)1.3.2 (including)
SafariApple2.0 (including)2.0 (including)
SafariApple2.0.2 (including)2.0.2 (including)
SafariApple2.0.4 (including)2.0.4 (including)
SafariApple3.0 (including)3.0 (including)
SafariApple3.0.2 (including)3.0.2 (including)
SafariApple3.0.3 (including)3.0.3 (including)
SafariApple3.0.4 (including)3.0.4 (including)
SafariApple3.1 (including)3.1 (including)
SafariApple3.1.1 (including)3.1.1 (including)
SafariApple3.1.2 (including)3.1.2 (including)
SafariApple3.2.1 (including)3.2.1 (including)
SafariApple3.2.3 (including)3.2.3 (including)
Red Hat Enterprise Linux 5RedHatkdegraphics-7:3.5.4-13.el5_3*
KdegraphicsUbuntudapper*
KdegraphicsUbuntuhardy*

References