WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Safari | Apple | * | 4.0.1 (including) |
Safari | Apple | 2.0 (including) | 2.0 (including) |
Safari | Apple | 2.0.0 (including) | 2.0.0 (including) |
Safari | Apple | 2.0.1 (including) | 2.0.1 (including) |
Safari | Apple | 2.0.2 (including) | 2.0.2 (including) |
Safari | Apple | 2.0.3 (including) | 2.0.3 (including) |
Safari | Apple | 2.0.3-417.8 (including) | 2.0.3-417.8 (including) |
Safari | Apple | 2.0.3-417.9 (including) | 2.0.3-417.9 (including) |
Safari | Apple | 2.0.3-417.9.2 (including) | 2.0.3-417.9.2 (including) |
Safari | Apple | 2.0.3-417.9.3 (including) | 2.0.3-417.9.3 (including) |
Safari | Apple | 2.0.4 (including) | 2.0.4 (including) |
Safari | Apple | 3.0 (including) | 3.0 (including) |
Safari | Apple | 3.0.0 (including) | 3.0.0 (including) |
Safari | Apple | 3.0.0b (including) | 3.0.0b (including) |
Safari | Apple | 3.0.1 (including) | 3.0.1 (including) |
Safari | Apple | 3.0.1-beta (including) | 3.0.1-beta (including) |
Safari | Apple | 3.0.1b (including) | 3.0.1b (including) |
Safari | Apple | 3.0.2 (including) | 3.0.2 (including) |
Safari | Apple | 3.0.2b (including) | 3.0.2b (including) |
Safari | Apple | 3.0.3 (including) | 3.0.3 (including) |
Safari | Apple | 3.0.3b (including) | 3.0.3b (including) |
Safari | Apple | 3.0.4 (including) | 3.0.4 (including) |
Safari | Apple | 3.0.4b (including) | 3.0.4b (including) |
Safari | Apple | 3.1.0 (including) | 3.1.0 (including) |
Safari | Apple | 3.1.0b (including) | 3.1.0b (including) |
Safari | Apple | 3.1.1 (including) | 3.1.1 (including) |
Safari | Apple | 3.1.2 (including) | 3.1.2 (including) |
Safari | Apple | 3.2.0 (including) | 3.2.0 (including) |
Safari | Apple | 3.2.1 (including) | 3.2.1 (including) |
Safari | Apple | 3.2.2 (including) | 3.2.2 (including) |
Safari | Apple | 4.0 (including) | 4.0 (including) |
Safari | Apple | 4.0.0b (including) | 4.0.0b (including) |
Kde4libs | Ubuntu | devel | * |
Kde4libs | Ubuntu | hardy | * |
Kde4libs | Ubuntu | intrepid | * |
Kde4libs | Ubuntu | jaunty | * |
Kde4libs | Ubuntu | karmic | * |
Kde4libs | Ubuntu | lucid | * |
Kde4libs | Ubuntu | maverick | * |
Kde4libs | Ubuntu | natty | * |
Kdelibs | Ubuntu | dapper | * |
Kdelibs | Ubuntu | devel | * |
Kdelibs | Ubuntu | hardy | * |
Kdelibs | Ubuntu | intrepid | * |
Kdelibs | Ubuntu | jaunty | * |
Kdelibs | Ubuntu | karmic | * |
Kdelibs | Ubuntu | lucid | * |
Kdelibs | Ubuntu | maverick | * |
Kdelibs | Ubuntu | natty | * |
Qt4-x11 | Ubuntu | intrepid | * |
Qt4-x11 | Ubuntu | jaunty | * |
Qt4-x11 | Ubuntu | karmic | * |
Webkit | Ubuntu | hardy | * |
Webkit | Ubuntu | intrepid | * |
Webkit | Ubuntu | jaunty | * |