Sploitus

CVE-2009-1709

1 known exploit for CVE-2009-1709

Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and unspecified "caches."

Affected products
Red Hat, Safari, Webcore, Webkit
Apple Safari
≤ 4.0_beta, 0.8, 0.9, 1.0, 1.0.3, 1.1, 1.2, 1.3, 1.3.1, 1.3.2, 2.0, 2.0.2, 2.0.4, 3.0, 3.0.2, 3.0.3, 3.0.4, 3.1, 3.1.1, 3.1.2, 3.2.1, 3.2.3
CVSS 2.0
9.3 HIGH
EPSS
6.9% (93th percentile)
Weakness
CWE-399
NVD status
Modified
Published
2009-06-10
CVE-2009-1709 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2009-1709

Proof-of-concept code and exploit modules indexed by Sploitus