## https://sploitus.com/exploit?id=SAINT:FE6436803A9F3E821D02CAEFCB83101E
Added: 09/16/2009
CVE: [CVE-2009-2195](<https://vulners.com/cve/CVE-2009-2195>)
BID: [36023](<http://www.securityfocus.com/bid/36023>)
OSVDB: [56988](<http://www.osvdb.org/56988>)
### Background
[Safari](<http://www.apple.com/safari/>) is a web browser for Mac OS X and Windows. Safari is built upon the [WebKit](<http://webkit.org/>) browser engine.
### Problem
A buffer overflow vulnerability in WebKit allows command execution when a user loads a page which contains a specially crafted floating point number.
### Resolution
[Upgrade](<http://www.apple.com/safari/download/>) to Safari 4.0.3 or higher.
### References
<http://support.apple.com/kb/HT3733>
### Limitations
Exploit works on Safari 4.0.2 and requires a user to load the exploit page.
After the page is loaded, there may be a delay before the exploit succeeds.
### Platforms
Windows XP
Mac OS X 10.4