WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.
                
            References
                    Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Configuration 2 (hide)
| AND | 
                                
                                
 
  | 
                        
Configuration 3 (hide)
| AND | 
                                
                                
 
  | 
                        
Information
                Published : 2009-07-09 10:30
Updated : 2022-08-09 06:48
NVD link : CVE-2009-1725
Mitre link : CVE-2009-1725
JSON object : View
CWE
                
                    
                        
                        CWE-189
                        
            Numeric Errors
Products Affected
                apple
- safari
 - ipod_touch
 - iphone_os
 


