CVE-2009-2419
Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML document that references a zero-length .js file and the JavaScript reload function. NOTE: some of these details are obtained from third party information.
- Apple Safari
- = 4.0, 4.0.1
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 9.1% (95th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2009-07-09
CVE-2009-2419 at NVD
1 known exploit for CVE-2009-2419
Proof-of-concept code and exploit modules indexed by Sploitus