vendor:
Safari
by:
John Cobb
7,5
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: Safari
Affected Version From: 4.0.4 (531.21.10)
Affected Version To: 4.0.4 (531.21.10)
Patch Exists: YES
Related CWE: N/A
CPE: apple:safari
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP (32-bit)
2010
Safari 4.0.4 (531.21.10) – Stack Overflow/run
This exploit is a proof-of-concept (POC) for a denial-of-service (DoS) vulnerability in Safari 4.0.4 (531.21.10). It was discovered by John Cobb in January 2010 and tested on Windows XP (32-bit) SP3. The exploit involves creating an HTML file with a background attribute containing a large number of 'A' characters. When the file is opened in Safari, the browser will crash due to a stack overflow.
Mitigation:
Users should update to the latest version of Safari to ensure that they are not vulnerable to this exploit.