Apple Security Advisories · July 2009 — Apple Security Advisories
7 advisories 7 CVEs

Apple-vendor CVEs for 2009-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2009-2419

SafariActive exploitation (sightings)CRITICAL2009-07-09

Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML document...

CVEs:CVE-2009-2419

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2009-1724

iOSEPSS <= 49%CRITICAL2009-07-09

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors rel...

CVEs:CVE-2009-1724

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
ipod_touch affected apple
safari affected apple
Upstream advisory

CVE-2009-1725

iOSEPSS <= 49%HIGH2009-07-09

WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character r...

CVEs:CVE-2009-1725

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
ipod_touch affected apple
safari affected apple
Upstream advisory

CVE-2009-1721

OtherEPSS <= 49%CRITICAL2009-07-31

The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an ...

CVEs:CVE-2009-1721

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2009-2422

OtherEPSS <= 49%CRITICAL2009-07-10

The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows c...

CVEs:CVE-2009-2422

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2009-2421

SafariEPSS <= 49%CRITICAL2009-07-09

The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a "high-bit character" in...

CVEs:CVE-2009-2421

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2009-2420

SafariEPSS <= 49%HIGH2009-07-09

Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitrary files or cause a denial of service (launch of multiple Windows Explorer instances) via vectors involving an unspecified HTML tag,...

CVEs:CVE-2009-2420

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.