CVE-2007-0342
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.
- Affected products
- Webkit
- Apple Safari
- = 2.0.4_419.3
- Apple Webkit
- = build_18794
- Omnigroup Omniweb
- = 5.5.3
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 2.2% (80th percentile)
- Weakness
- CWE-399, CWE-476
- NVD status
- Modified
- Published
- 2007-01-18
CVE-2007-0342 at NVD
1 known exploit for CVE-2007-0342
Proof-of-concept code and exploit modules indexed by Sploitus