Apple Security Advisories · January 2009 — Apple Security Advisories
20 advisories 20 CVEs

Apple-vendor CVEs for 2009-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2009-0070

SafariActive exploitation (sightings)HIGH2009-01-08

Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably have unspecified other impact via the array index of the arguments array in...

CVEs:CVE-2009-0070

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2009-0321

SafariActive exploitation (sightings)HIGH2009-01-28

Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (do...

CVEs:CVE-2009-0321

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2009-0003

OtherEPSS <= 49%HIGH2009-01-21

Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via an AVI movie file with an invalid nBlockAlign value in the _WAVEFORMATEX structure.

CVEs:CVE-2009-0003

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2009-1698

iOSEPSS <= 49%HIGH2009-01-14

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which all...

CVEs:CVE-2009-1698

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
ipod_touch affected apple
safari affected apple
Upstream advisory

CVE-2009-0006

OtherEPSS <= 49%HIGH2009-01-21

Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Cinepak encoded movie file with a crafted MDAT atom that triggers a heap-bas...

CVEs:CVE-2009-0006

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2009-1687

iOSEPSS <= 49%HIGH2009-01-14

The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle allocation failures, which allows remote attackers to execute arbitrary code or ...

CVEs:CVE-2009-1687

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2009-0002

OtherEPSS <= 49%HIGH2009-01-21

Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QTVR movie file with crafted THKD atoms.

CVEs:CVE-2009-0002

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2009-1712

SafariEPSS <= 49%HIGH2009-01-14

WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element.

CVEs:CVE-2009-1712

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2009-0007

OtherEPSS <= 49%HIGH2009-01-21

Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms wit...

CVEs:CVE-2009-0007

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2009-1709

SafariEPSS <= 49%HIGH2009-01-14

Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG anim...

CVEs:CVE-2009-1709

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2009-0001

OtherEPSS <= 49%HIGH2009-01-21

Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted RTSP URL.

CVEs:CVE-2009-0001

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2009-1711

SafariEPSS <= 49%HIGH2009-01-14

WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.

CVEs:CVE-2009-1711

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2009-1690

iOSEPSS <= 49%HIGH2009-01-14

Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary cod...

CVEs:CVE-2009-1690

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2009-0004

OtherEPSS <= 49%HIGH2009-01-21

Buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted MP3 audio file.

CVEs:CVE-2009-0004

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2009-0005

OtherEPSS <= 49%HIGH2009-01-21

Unspecified vulnerability in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted H.263 encoded movie file that triggers memory corruption.

CVEs:CVE-2009-0005

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2009-0008

OtherEPSS <= 49%CRITICAL2009-01-22

Unspecified vulnerability in Apple QuickTime MPEG-2 Playback Component before 7.60.92.0 on Windows allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted MPEG-2 movie.

CVEs:CVE-2009-0008

Affected products

ProductStatusVendorPackageEcosystem
quicktime_mpeg-2_playback_component affected apple
Upstream advisory

CVE-2008-5821

SafariEPSS <= 49%HIGH2009-01-02

Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause a denial of service (memory consumption and browser crash) via a long ALINK attribute in a BODY element in an HTML document.

CVEs:CVE-2008-5821

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2009-0123

macOSEPSS <= 49%HIGH2009-01-15

Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for R...

CVEs:CVE-2009-0123

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2008-5914

SafariEPSS <= 49%LOW2009-01-20

An unspecified function in the JavaScript implementation in Apple Safari creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-...

CVEs:CVE-2008-5914

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2009-0032

OtherEPSS <= 49%MEDIUM2009-01-27

CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.

CVEs:CVE-2009-0032

Affected products

ProductStatusVendorPackageEcosystem
cups affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.