VDB
CVE-2009-2419
CVE-2009-2419
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML document that references a zero-length .js file and the JavaScript reload function. NOTE: some of these details are obtained from third party information.
EPSS 9.07% · 94.8th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
9.07%
94.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| apple | safari | 4.0, 4.0.1 |
Timeline
- Jun 2, 2009 PoC Published
- Jul 9, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Jul 17, 2022 EPSS Score
- Jul 18, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- 43068 third-party-advisory
- ADV-2011-0212 vdb
- http://trac.webkit.org/changeset/44519 url
- 55587 vdb
- 35555 vdb
- SUSE-SR:2011:002 vendor-advisory
- safari-servependingrequests-dos(51533) vdb
- http://marcell-dietl.de/index/adv_safari_4_x_js_reload_dos.php url
- 33495 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2009-2419 advisory