CVE-2009-0945
Summary
| CVE | CVE-2009-0945 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-05-13 17:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4) SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object, which triggers memory corruption. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | 10.4.11 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.0 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.1 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.2 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.3 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.4 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.5 | All | All | All |
| Operating System | Apple | Mac Os X | 10.5.6 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.4.11 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.5.0 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.5.1 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.5.2 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.5.3 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.5.4 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.5.6 | All | All | All |
| Application | Apple | Safari | 0.8 | All | All | All |
| Application | Apple | Safari | 0.9 | All | All | All |
| Application | Apple | Safari | 1.0 | All | All | All |
| Application | Apple | Safari | 1.0 | beta | All | All |
| Application | Apple | Safari | 1.0 | beta2 | All | All |
| Application | Apple | Safari | 1.0.0 | All | All | All |
| Application | Apple | Safari | 1.0.0b1 | All | All | All |
| Application | Apple | Safari | 1.0.0b2 | All | All | All |
| Application | Apple | Safari | 1.0.1 | All | All | All |
| Application | Apple | Safari | 1.0.2 | All | All | All |
| Application | Apple | Safari | 1.0.3 | All | All | All |
| Application | Apple | Safari | 1.0.3 | 85.8 | All | All |
| Application | Apple | Safari | 1.0.3 | 85.8.1 | All | All |
| Application | Apple | Safari | 1.1 | All | All | All |
| Application | Apple | Safari | 1.1.0 | All | All | All |
| Application | Apple | Safari | 1.1.1 | All | All | All |
| Application | Apple | Safari | 1.2 | All | All | All |
| Application | Apple | Safari | 1.2.0 | All | All | All |
| Application | Apple | Safari | 1.2.1 | All | All | All |
| Application | Apple | Safari | 1.2.2 | All | All | All |
| Application | Apple | Safari | 1.2.3 | All | All | All |
| Application | Apple | Safari | 1.2.4 | All | All | All |
| Application | Apple | Safari | 1.2.5 | All | All | All |
| Application | Apple | Safari | 1.3 | All | All | All |
| Application | Apple | Safari | 1.3.0 | All | All | All |
| Application | Apple | Safari | 1.3.1 | All | All | All |
| Application | Apple | Safari | 1.3.2 | All | All | All |
| Application | Apple | Safari | 1.3.2 | 312.5 | All | All |
| Application | Apple | Safari | 1.3.2 | 312.6 | All | All |
| Application | Apple | Safari | 2 | All | All | All |
| Application | Apple | Safari | 2.0 | All | All | All |
| Application | Apple | Safari | 2.0.0 | All | All | All |
| Application | Apple | Safari | 2.0.1 | All | All | All |
| Application | Apple | Safari | 2.0.2 | All | All | All |
| Application | Apple | Safari | 2.0.3 | All | All | All |
| Application | Apple | Safari | 2.0.3 | 417.8 | All | All |
| Application | Apple | Safari | 2.0.3 | 417.9 | All | All |
| Application | Apple | Safari | 2.0.3 | 417.9.2 | All | All |
| Application | Apple | Safari | 2.0.4 | All | All | All |
| Application | Apple | Safari | 3 | All | All | All |
| Application | Apple | Safari | 3.0 | All | All | All |
| Application | Apple | Safari | 3.0.0 | All | All | All |
| Application | Apple | Safari | 3.0.1 | All | All | All |
| Application | Apple | Safari | 3.0.2 | All | All | All |
| Application | Apple | Safari | 3.0.3 | All | All | All |
| Application | Apple | Safari | 3.0.4 | All | All | All |
| Application | Apple | Safari | 3.1 | All | All | All |
| Application | Apple | Safari | 3.1.0 | All | All | All |
| Application | Apple | Safari | 3.1.1 | All | All | All |
| Application | Apple | Safari | 3.1.2 | All | All | All |
| Application | Apple | Safari | 3.2 | All | All | All |
| Application | Apple | Safari | 3.2.0 | All | All | All |
| Application | Apple | Safari | 3.2.1 | All | All | All |
| Application | Apple | Safari | 4.0 | beta | All | All |
| Application | Apple | Safari | All | All | All | All |
| Operating System | Microsoft | Windows Vista | All | All | All | All |
| Operating System | Microsoft | Windows Xp | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About the security content of iPhone OS 3.0 Software Update | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| SUSE update for Multiple Packages - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 10 Update: kdelibs-4.2.4-6.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Debian -- Security Information -- DSA-1950-1 webkit | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| APPLE-SA-2009-05-12 Security Update 2009-002 / Mac OS X v10.5.7 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Patch, Vendor Advisory |
| About the security content of Security Update 2009-002 / Mac OS X v10.5.7 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2011:002 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Apple Safari Buffer Overflow in WebKit in Processing SVGList Objects Lets Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Red Hat update for kdegraphics - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 11 Update: webkitgtk-1.1.8-1.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| APPLE-SA-2009-05-12 Safari 3.2.3 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Apple Safari Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Fedora update for webkitgtk - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Debian update for webkit - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Google Chrome WebKit SVGList Object Handling Memory Corruption - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| USN-857-1: Qt vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| APPLE-SA-2009-05-12 Safari 4 Public Beta Security Update | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Patch, Vendor Advisory |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| APPLE-SA-2009-06-17-1 iPhone OS 3.0 Software Update | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Fedora update for kdelibs - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 11 Update: kdelibs-4.2.4-6.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| USN-823-1: KDE-Graphics vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| USN-822-1: KDE-Libs vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| USN-836-1: WebKit vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Issue 9019 - chromium - zdi-can-464: malformed svglist parsing code execution - An open-source project to help move the web forward. - Google Project Hosting | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | |
| Google Chrome Releases: Stable Update: Bug fix | af854a3a-2127-422b-91ae-364da2661108 | googlechromereleases.blogspot.com | |
| About the security content of Safari 3.2.3 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| US-CERT Technical Cyber Security Alert TA09-133A -- Apple Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Ubuntu update for kdegraphics - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 504 Gateway Time-out | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.