CVE-2009-2804
Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an image, leading to a heap-based buffer overflow.
- Apple Mac Os X
- = 10.4.11, 10.5.8
- Apple Mac Os X Server
- = 10.4.11, 10.5.8
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 4.5% (91th percentile)
- Weakness
- CWE-189
- NVD status
- Modified
- Published
- 2009-09-14
CVE-2009-2804 at NVD
2 known exploits for CVE-2009-2804
Proof-of-concept code and exploit modules indexed by Sploitus