APPLE-SA-2009-08-11-1Vendor advisory
http://lists.apple.com/archives/security-announce/2009/Aug/msg00002.html CVE-2009-2195
WebKit - Floating Point Number Remote Buffer Overflow
Record summary
CVE-2009-2195 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted floating-point numbers.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWebKit - Floating Point Number Remote Buffer OverflowExploitDB exploitby AppleNot analyzed1 file
References
10APPLE-SA-2010-06-21-1Vendor advisory
http://lists.apple.com/archives/security-announce/2010/Jun/msg00003.html SUSE-SR:2011:002Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html 43068Third-party advisory
http://secunia.com/advisories/43068 support.apple.comConfirmation
http://support.apple.com/kb/HT3733 support.apple.comConfirmation
http://support.apple.com/kb/HT4225 36023vdb entry
http://www.securityfocus.com/bid/36023 1022717vdb entry
http://www.securitytracker.com/id?1022717 ADV-2011-0212vdb entry
http://www.vupen.com/english/advisories/2011/0212 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-2195