Search CVE reports


Toggle filters

311 – 320 of 356 results


CVE-2009-3933

Low priority
Ignored

WebKit before r50173, as used in Google Chrome before 3.0.195.32, allows remote attackers to cause a denial of service (CPU consumption) via a web page that calls the JavaScript setInterval method, which triggers...

4 affected packages

kde4libs, kdelibs, qt4-x11, webkit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
kde4libs
kdelibs
qt4-x11
webkit
Show less packages

CVE-2009-2797

Low priority

Some fixes available 1 of 8

The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive...

2 affected packages

qt4-x11, webkit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt4-x11
webkit
Show less packages

CVE-2009-2700

Medium priority

Some fixes available 4 of 5

src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to...

1 affected package

qt4-x11

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt4-x11
Show less packages

CVE-2009-3015

Low priority
Ignored

QtWeb 3.0 Builds 001 and 003 does not properly block javascript: and data: URIs in Refresh and Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to...

4 affected packages

webkit, kde4libs, kdelibs, qt4-x11

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
webkit
kde4libs
kdelibs
qt4-x11
Show less packages

CVE-2009-2200

Low priority
Ignored

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive...

4 affected packages

webkit, kdelibs, kde4libs, qt4-x11

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
webkit
kdelibs
kde4libs
qt4-x11
Show less packages

CVE-2009-2195

Medium priority
Ignored

Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted floating-point numbers.

2 affected packages

qt4-x11, webkit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt4-x11
webkit
Show less packages

CVE-2009-1724

Low priority
Ignored

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script...

2 affected packages

qt4-x11, webkit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt4-x11
webkit
Show less packages

CVE-2009-2419

Medium priority
Ignored

Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a...

2 affected packages

qt4-x11, webkit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt4-x11
webkit
Show less packages

CVE-2009-1725

Medium priority

Some fixes available 4 of 21

WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly...

4 affected packages

webkit, kde4libs, kdelibs, qt4-x11

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
webkit
kde4libs
kdelibs
qt4-x11
Show less packages

CVE-2009-1692

Low priority
Ignored

WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows remote attackers to cause a denial of service (memory consumption or device reset)...

2 affected packages

qt4-x11, webkit

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt4-x11
webkit
Show less packages