vendor:
Safari
by:
Lostmon
5.5
CVSS
MEDIUM
Denial-of-Service
20
CWE
Product Name: Safari
Affected Version From: Safari 3.0.1 beta for Windows
Affected Version To: Safari 3.0.1 beta for Windows
Patch Exists: NO
Related CWE:
CPE: a:apple:safari:3.0.1
Platforms Tested: Windows
2007
Denial-of-Service Vulnerability in Apple Safari for Windows
Apple Safari for Windows is prone to a denial-of-service vulnerability because it fails to properly handle user-supplied input. An attacker may exploit this issue by enticing victims into opening a maliciously crafted HTML document. Successful exploits can allow attackers to crash the affected browser, resulting in denial-of-service conditions. Attackers may also be able to execute arbitrary code, but Symantec had not confirmed this.
Mitigation:
Update to a patched version of Apple Safari for Windows.