CVE Database
/

CVE-2009-2804

Back to search

CVE-2009-2804

Published: Sep 14, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an image, leading to a heap-based buffer overflow.

VendorProductVersions

n/a

n/a

affected
n/a

References

APPLE-SA-2009-11-11-1
vendor-advisory
x_refsource_APPLE
ADV-2009-3217
vdb-entry
x_refsource_VUPEN
36357
vdb-entry
x_refsource_BID
APPLE-SA-2009-09-10-2
vendor-advisory
x_refsource_APPLE
apple-macosx-colosync-bo(53166)
vdb-entry
x_refsource_XF
36701
third-party-advisory
x_refsource_SECUNIA
57949
vdb-entry
x_refsource_OSVDB
37346
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now