CVE-2009-1709
Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and unspecified "caches."
- Apple Safari
- ≤ 4.0_beta, 0.8, 0.9, 1.0, 1.0.3, 1.1, 1.2, 1.3, 1.3.1, 1.3.2, 2.0, 2.0.2, 2.0.4, 3.0, 3.0.2, 3.0.3, 3.0.4, 3.1, 3.1.1, 3.1.2, 3.2.1, 3.2.3
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 6.9% (93th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2009-06-10
CVE-2009-1709 at NVD
1 known exploit for CVE-2009-1709
Proof-of-concept code and exploit modules indexed by Sploitus