Vulnerability Name: | CVE-2006-1988 (CCN-25946) | ||||||||
Assigned: | 2006-04-19 | ||||||||
Published: | 2006-04-19 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | The WebTextRenderer(WebInternal) _CG_drawRun:style:geometry: function in Apple Safari 2.0.3 allows remote attackers to cause a denial of service (application crash) via an HTML LI tag with a large VALUE attribute (list item number), which triggers a null dereference in QPainter::drawText, probably due to a failed memory allocation that uses the VALUE. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-1986 Source: MITRE Type: CNA CVE-2006-1987 Source: MITRE Type: CNA CVE-2006-1988 Source: CCN Type: SA19686 Mac OS X Multiple Potential Vulnerabilities Source: SECUNIA Type: UNKNOWN 19686 Source: MISC Type: UNKNOWN http://security-protocols.com/poc/sp-x26-2.html Source: OSVDB Type: UNKNOWN 24823 Source: CCN Type: OSVDB ID: 24823 Apple Safari Multiple Function DoS Source: CCN Type: Security-Protocols Advisory April 19th, 2006 Apple OS X Safari 2.0.3 Multiple Vulnerabilities Source: MISC Type: Exploit, Vendor Advisory http://www.security-protocols.com/sp-x26-advisory.php Source: BID Type: Exploit 17634 Source: CCN Type: BID-17634 Apple Mac OS X Multiple Security Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2006-1452 Source: XF Type: UNKNOWN macosx-safari-dos(25946) Source: XF Type: UNKNOWN macosx-safari-dos(25946) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |