ID

VAR-200902-0667


CVE

CVE-2009-0744


TITLE

Apple Safari Denial of service in Japan (DoS) Vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2009-001573

DESCRIPTION

Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a feeds: URI beginning with a (1) % (percent), (2) { (open curly bracket), (3) } (close curly bracket), (4) ^ (caret), (5) ` (backquote), or (6) | (pipe) character, followed by an & (ampersand) character. Apple Safari is prone to a denial-of-service vulnerability that stems from a NULL-pointer dereference. Attackers can exploit this issue to crash the affected application, denying service to legitimate users. Apple Safari 4 Beta is vulnerable; other versions may also be affected. Safari is the web browser bundled by default in the Apple family operating system. Malformed feeds in Apple Safari: URI Null Pointer Reference Denial of Service Vulnerability. Since the user input provided in the feeds: URI is not adequately filtered, if the user is tricked into following a malicious link, a null pointer dereference will be triggered, causing the Safari process to crash

Trust: 1.98

sources: NVD: CVE-2009-0744 // JVNDB: JVNDB-2009-001573 // BID: 33909 // VULHUB: VHN-38190

AFFECTED PRODUCTS

vendor:applemodel:safariscope:eqversion:4.0

Trust: 1.6

vendor:applemodel:safariscope:eqversion:4 beta build 528.16

Trust: 0.8

vendor:applemodel:safari betascope:eqversion:4

Trust: 0.3

sources: BID: 33909 // JVNDB: JVNDB-2009-001573 // CNNVD: CNNVD-200902-665 // NVD: CVE-2009-0744

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-0744
value: MEDIUM

Trust: 1.0

NVD: CVE-2009-0744
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200902-665
value: MEDIUM

Trust: 0.6

VULHUB: VHN-38190
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2009-0744
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-38190
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-38190 // JVNDB: JVNDB-2009-001573 // CNNVD: CNNVD-200902-665 // NVD: CVE-2009-0744

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-38190 // JVNDB: JVNDB-2009-001573 // NVD: CVE-2009-0744

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200902-665

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-200902-665

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-001573

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-38190

PATCH

title:Top Pageurl:http://www.apple.com/safari/

Trust: 0.8

sources: JVNDB: JVNDB-2009-001573

EXTERNAL IDS

db:NVDid:CVE-2009-0744

Trust: 2.8

db:BIDid:33909

Trust: 2.0

db:JVNDBid:JVNDB-2009-001573

Trust: 0.8

db:CNNVDid:CNNVD-200902-665

Trust: 0.7

db:XFid:48943

Trust: 0.6

db:BUGTRAQid:20090225 APPLE SAFARI 4 BETA FEEDS: URI NULL POINTER DEREFERENCE DENIAL OF SERVICE VULNERABILITY

Trust: 0.6

db:SEEBUGid:SSVID-86086

Trust: 0.1

db:EXPLOIT-DBid:32817

Trust: 0.1

db:VULHUBid:VHN-38190

Trust: 0.1

sources: VULHUB: VHN-38190 // BID: 33909 // JVNDB: JVNDB-2009-001573 // CNNVD: CNNVD-200902-665 // NVD: CVE-2009-0744

REFERENCES

url:http://www.securityfocus.com/bid/33909

Trust: 1.7

url:http://www.securityfocus.com/archive/1/501229/100/0/threaded

Trust: 1.1

url:https://oval.cisecurity.org/repository/search/definition/oval%3aorg.mitre.oval%3adef%3a6066

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/48943

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-0744

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-0744

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/48943

Trust: 0.6

url:http://www.securityfocus.com/archive/1/archive/1/501229/100/0/threaded

Trust: 0.6

url:http://www.apple.com/safari/

Trust: 0.3

url:/archive/1/501229

Trust: 0.3

sources: VULHUB: VHN-38190 // BID: 33909 // JVNDB: JVNDB-2009-001573 // CNNVD: CNNVD-200902-665 // NVD: CVE-2009-0744

CREDITS

Trancer mtrancer@gmail.com

Trust: 0.6

sources: CNNVD: CNNVD-200902-665

SOURCES

db:VULHUBid:VHN-38190
db:BIDid:33909
db:JVNDBid:JVNDB-2009-001573
db:CNNVDid:CNNVD-200902-665
db:NVDid:CVE-2009-0744

LAST UPDATE DATE

2025-04-10T23:16:31.772000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-38190date:2018-10-10T00:00:00
db:BIDid:33909date:2015-04-13T21:11:00
db:JVNDBid:JVNDB-2009-001573date:2009-07-08T00:00:00
db:CNNVDid:CNNVD-200902-665date:2009-03-02T00:00:00
db:NVDid:CVE-2009-0744date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-38190date:2009-02-27T00:00:00
db:BIDid:33909date:2009-02-25T00:00:00
db:JVNDBid:JVNDB-2009-001573date:2009-07-08T00:00:00
db:CNNVDid:CNNVD-200902-665date:2009-02-27T00:00:00
db:NVDid:CVE-2009-0744date:2009-02-27T17:30:09.907