NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
55339  CVE-2007-3185  Apple Safari Beta 3.0.1 for Windows public beta allows remote attackers to cause a denial of service (crash) via unspecified DHTML manipulations that trigger memory corruption, as demonstrated using Hamachi.    7.8  High  2017-01-07  2011-03-07  View
7022  CVE-2008-7296  Apple Safari cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.    5.8  Medium  2017-01-03  2012-08-02  View
49328  CVE-2009-2066  Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site"s context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."    6.8  Medium  2017-01-07  2009-06-24  View
13924  CVE-2010-2454  Apple Safari does not properly manage the address bar between the request to open a URL and the retrieval of the new document"s content, which might allow remote attackers to conduct spoofing attacks via a crafted HTML document, a related issue to CVE-2010-1206.    4.3  Medium  2017-01-18  2012-11-05  View
49334  CVE-2009-2072  Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to spoof an arbitrary https site by sending the browser a crafted (1) 4xx or (2) 5xx CONNECT response page for an https request sent through a proxy server.    5.4  Medium  2017-01-07  2009-06-23  View

Page 1348 of 17672, showing 5 records out of 88360 total, starting on record 6736, ending on 6740

Actions