CVE Vulnerabilities

CVE-2009-1725

Published: Jul 09, 2009 | Modified: Aug 09, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.

Affected Software

Name Vendor Start Version End Version
Safari Apple * 4.0.1 (including)
Safari Apple 2.0 (including) 2.0 (including)
Safari Apple 2.0.0 (including) 2.0.0 (including)
Safari Apple 2.0.1 (including) 2.0.1 (including)
Safari Apple 2.0.2 (including) 2.0.2 (including)
Safari Apple 2.0.3 (including) 2.0.3 (including)
Safari Apple 2.0.3-417.8 (including) 2.0.3-417.8 (including)
Safari Apple 2.0.3-417.9 (including) 2.0.3-417.9 (including)
Safari Apple 2.0.3-417.9.2 (including) 2.0.3-417.9.2 (including)
Safari Apple 2.0.3-417.9.3 (including) 2.0.3-417.9.3 (including)
Safari Apple 2.0.4 (including) 2.0.4 (including)
Safari Apple 3.0 (including) 3.0 (including)
Safari Apple 3.0.0 (including) 3.0.0 (including)
Safari Apple 3.0.0b (including) 3.0.0b (including)
Safari Apple 3.0.1 (including) 3.0.1 (including)
Safari Apple 3.0.1-beta (including) 3.0.1-beta (including)
Safari Apple 3.0.1b (including) 3.0.1b (including)
Safari Apple 3.0.2 (including) 3.0.2 (including)
Safari Apple 3.0.2b (including) 3.0.2b (including)
Safari Apple 3.0.3 (including) 3.0.3 (including)
Safari Apple 3.0.3b (including) 3.0.3b (including)
Safari Apple 3.0.4 (including) 3.0.4 (including)
Safari Apple 3.0.4b (including) 3.0.4b (including)
Safari Apple 3.1.0 (including) 3.1.0 (including)
Safari Apple 3.1.0b (including) 3.1.0b (including)
Safari Apple 3.1.1 (including) 3.1.1 (including)
Safari Apple 3.1.2 (including) 3.1.2 (including)
Safari Apple 3.2.0 (including) 3.2.0 (including)
Safari Apple 3.2.1 (including) 3.2.1 (including)
Safari Apple 3.2.2 (including) 3.2.2 (including)
Safari Apple 4.0 (including) 4.0 (including)
Safari Apple 4.0.0b (including) 4.0.0b (including)
Kde4libs Ubuntu devel *
Kde4libs Ubuntu hardy *
Kde4libs Ubuntu intrepid *
Kde4libs Ubuntu jaunty *
Kde4libs Ubuntu karmic *
Kde4libs Ubuntu lucid *
Kde4libs Ubuntu maverick *
Kde4libs Ubuntu natty *
Kdelibs Ubuntu dapper *
Kdelibs Ubuntu devel *
Kdelibs Ubuntu hardy *
Kdelibs Ubuntu intrepid *
Kdelibs Ubuntu jaunty *
Kdelibs Ubuntu karmic *
Kdelibs Ubuntu lucid *
Kdelibs Ubuntu maverick *
Kdelibs Ubuntu natty *
Qt4-x11 Ubuntu intrepid *
Qt4-x11 Ubuntu jaunty *
Qt4-x11 Ubuntu karmic *
Webkit Ubuntu hardy *
Webkit Ubuntu intrepid *
Webkit Ubuntu jaunty *

References