CVE-2009-1690
Summary
| CVE | CVE-2009-1690 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-06-10 14:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by setting an unspecified property of an HTML tag that causes child elements to be freed and later accessed when an HTML error occurs, related to "recursion in certain DOM event handlers." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Iphone Os | 1.0 | All | All | All |
| Operating System | Apple | Iphone Os | 1.0.0 | All | All | All |
| Operating System | Apple | Iphone Os | 1.0.1 | All | All | All |
| Operating System | Apple | Iphone Os | 1.0.1 | - | iphone | All |
| Operating System | Apple | Iphone Os | 1.0.2 | All | All | All |
| Operating System | Apple | Iphone Os | 1.0.2 | - | iphone | All |
| Operating System | Apple | Iphone Os | 1.1 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.0 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.0 | - | iphone | All |
| Operating System | Apple | Iphone Os | 1.1.0 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 1.1.1 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.1 | - | iphone | All |
| Operating System | Apple | Iphone Os | 1.1.2 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.2 | - | iphone | All |
| Operating System | Apple | Iphone Os | 1.1.2 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 1.1.3 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.3 | - | iphone | All |
| Operating System | Apple | Iphone Os | 1.1.3 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 1.1.4 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.4 | - | iphone | All |
| Operating System | Apple | Iphone Os | 1.1.4 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 1.1.5 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.5 | - | iphone | All |
| Operating System | Apple | Iphone Os | 1.1.5 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 2.0 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0.0 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0.0 | - | iphone | All |
| Operating System | Apple | Iphone Os | 2.0.0 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 2.0.1 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0.1 | - | iphone | All |
| Operating System | Apple | Iphone Os | 2.0.1 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 2.0.2 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0.2 | - | iphone | All |
| Operating System | Apple | Iphone Os | 2.0.2 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 2.1 | All | All | All |
| Operating System | Apple | Iphone Os | 2.1 | - | iphone | All |
| Operating System | Apple | Iphone Os | 2.1 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 2.2 | - | iphone | All |
| Operating System | Apple | Iphone Os | 2.2 | - | ipodtouch | All |
| Operating System | Apple | Iphone Os | 2.2.1 | - | iphone | All |
| Operating System | Apple | Iphone Os | 2.2.1 | - | ipodtouch | All |
| Application | Apple | Safari | 0.8 | All | mac | All |
| Application | Apple | Safari | 0.9 | All | mac | All |
| Application | Apple | Safari | 1.0 | All | mac | All |
| Application | Apple | Safari | 1.0.3 | All | mac | All |
| Application | Apple | Safari | 1.1 | All | mac | All |
| Application | Apple | Safari | 1.2 | All | mac | All |
| Application | Apple | Safari | 1.3 | All | mac | All |
| Application | Apple | Safari | 1.3.1 | All | mac | All |
| Application | Apple | Safari | 1.3.2 | All | mac | All |
| Application | Apple | Safari | 2.0 | All | mac | All |
| Application | Apple | Safari | 2.0.2 | All | mac | All |
| Application | Apple | Safari | 2.0.4 | All | mac | All |
| Application | Apple | Safari | 3.0 | All | mac | All |
| Application | Apple | Safari | 3.0 | All | windows | All |
| Application | Apple | Safari | 3.0.1 | All | windows | All |
| Application | Apple | Safari | 3.0.2 | All | windows | All |
| Application | Apple | Safari | 3.0.2 | - | mac | All |
| Application | Apple | Safari | 3.0.3 | All | mac | All |
| Application | Apple | Safari | 3.0.3 | All | windows | All |
| Application | Apple | Safari | 3.0.4 | All | mac | All |
| Application | Apple | Safari | 3.0.4 | All | windows | All |
| Application | Apple | Safari | 3.1 | All | mac | All |
| Application | Apple | Safari | 3.1 | All | windows | All |
| Application | Apple | Safari | 3.1.1 | All | mac | All |
| Application | Apple | Safari | 3.1.1 | All | windows | All |
| Application | Apple | Safari | 3.1.2 | All | mac | All |
| Application | Apple | Safari | 3.1.2 | All | windows | All |
| Application | Apple | Safari | 3.2 | - | windows | All |
| Application | Apple | Safari | 3.2.1 | All | mac | All |
| Application | Apple | Safari | 3.2.1 | All | windows | All |
| Application | Apple | Safari | 3.2.2 | All | windows | All |
| Application | Apple | Safari | 3.2.3 | All | mac | All |
| Application | Apple | Safari | All | All | windows | All |
| Application | Apple | Safari | All | All | mac | All |
| Application | Chrome | 1.0.154.53 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About the security content of iPhone OS 3.0 Software Update | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Patch, Vendor Advisory |
| SUSE update for Multiple Packages - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [SECURITY] Fedora 10 Update: kdelibs-4.2.4-6.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| About the security content of Safari 4.0 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| RETIRED: Apple Safari Prior to 4.0 Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| Debian -- Security Information -- DSA-1950-1 webkit | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2011:002 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Fedora update for kdelibs3 - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian update for webkit - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| USN-857-1: Qt vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| SecurityTracker.com Archives - Apple Safari Bugs Let Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Patch |
| osvdb.org/54990 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Security Alerts - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| APPLE-SA-2009-06-17-1 iPhone OS 3.0 Software Update | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Patch, Vendor Advisory |
| APPLE-SA-2009-06-08-1 Safari 4.0 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Patch, Vendor Advisory |
| Fedora update for kdelibs - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [SECURITY] Fedora 11 Update: kdelibs-4.2.4-6.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Support / Security / Advisories / / MDVSA-2009:330 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| USN-822-1: KDE-Libs vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| Apple Safari Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| USN-836-1: WebKit vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [SECURITY] Fedora 11 Update: kdelibs3-3.5.10-13.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Public Advisory: 06.08.09 // iDefense Labs | af854a3a-2127-422b-91ae-364da2661108 | labs.idefense.com | |
| [SECURITY] Fedora 10 Update: kdelibs3-3.5.10-13.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.