|
290751
|
- |
|
apple
|
safari
|
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a differen…
|
NVD-CWE-noinfo
|
CVE-2012-3589
|
2024-11-21 10:41 |
2012-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290752
|
- |
|
apple
|
safari
|
WebKit in Apple Safari before 6.0 does not properly handle file: URLs, which allows remote attackers to bypass intended sandbox restrictions and read arbitrary files by leveraging a WebProcess compro…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3697
|
2024-11-21 10:41 |
2012-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290753
|
- |
|
apple
|
safari
|
CRLF injection vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP request splitting attacks via a crafted web site that lever…
|
CWE-20
Improper Input Validation
|
CVE-2012-3696
|
2024-11-21 10:41 |
2012-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290754
|
- |
|
apple
|
safari
|
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary web script or HTML by leveraging improper URL canonicalization during the han…
|
CWE-79
Cross-site Scripting
|
CVE-2012-3695
|
2024-11-21 10:41 |
2012-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290755
|
- |
|
apple
|
safari
|
WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to obtain sensitive information about full pathnames via a crafted web sit…
|
CWE-200
Information Exposure
|
CVE-2012-3694
|
2024-11-21 10:41 |
2012-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290756
|
- |
|
apple
|
safari
|
Incomplete blacklist vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, by leveraging the availability of…
|
NVD-CWE-Other
|
CVE-2012-3693
|
2024-11-21 10:41 |
2012-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290757
|
- |
|
apple
|
safari
|
WebKit in Apple Safari before 6.0 does not properly handle Cascading Style Sheets (CSS) property values, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.
|
CWE-20
Improper Input Validation
|
CVE-2012-3691
|
2024-11-21 10:41 |
2012-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290758
|
- |
|
apple
|
safari
|
WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to read arbitrary files via a crafted web site.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-3690
|
2024-11-21 10:41 |
2012-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290759
|
- |
|
apple
|
safari
|
WebKit in Apple Safari before 6.0 does not properly handle drag-and-drop events, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site.
|
CWE-20
Improper Input Validation
|
CVE-2012-3689
|
2024-11-21 10:41 |
2012-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290760
|
- |
|
apple
|
safari
|
WebKit in Apple Safari before 6.0 accesses uninitialized memory locations during the rendering of SVG images, which allows remote attackers to obtain sensitive information from process memory via a c…
|
CWE-200
Information Exposure
|
CVE-2012-3650
|
2024-11-21 10:41 |
2012-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|