Breaking News

Arctic announces Senza AI 370 Under Desk PC for AI Applications CORSAIR Announces the Airflow-focused 3200D Mid Tower for Ambitious DIY PC Builds Silicon Power Launches Enterprise-Grade DDR5 RDIMM to Accelerate AI Workloads World Backup Day 2026: A Backup Doesn’t Always Need to be in the Cloud Sharkoon announces S100 ARGB AIO Cooler

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Researchers Reveal Important Safari Vulnerability

Researchers Reveal Important Safari Vulnerability

Enterprise & IT May 11,2010 0

Danish vulnerability tracker Secunia found a vulnerability and a security issue in Apple's Safari browser. According to Secunia, the security issue can lead to exposure of sensitive information and the vulnerability can be exploited by malicious people to compromise a user's system.

An error in the handling of parent windows can result in a function call using an invalid pointer. This can be exploited to execute arbitrary code when a user e.g. visits a specially crafted web page and closes opened pop-up windows, Secunia announced.

The security issue is caused due to Safari including HTTP basic authentication credentials in an HTTP request if a web page that requires HTTP basic authentication redirects to a different domain (e.g. via a "Location" header).

The vulnerability and the security issue are confirmed in Safari version 4.0.5 for Windows.

The company recommends users not to visit untrusted web sites or follow links from untrusted sources. In addition, users should not authenticate to sites that use HTTP basic authentication and use redirections to different domains.

US-CERT also confirmed the vulnerability affecting Apple Safari.

"By convincing a user to open a specially crafted web page, an attacker may be able to execute arbitrary code. Exploit code for this vulnerability is publicly available," US-CERT said.

US-CERT encourages users and administrators to disable JavaScript until a fix is provided by Apple.

Tags: safariApple
Previous Post
Sharp Develops 3D Camera Module for Mobile Devices Capable of Capturing HD 3D Video
Next Post
Report: $51 Billion Lost to Software Piracy in 2009

Related Posts

  • Apple introduces AirPods Max 2

  • Apple introduces the new M5 Pro/Max powered laptops and new Studio Display

  • Apple introduces iPhone 17e and new new iPad Air

  • Apple introduces new AirTag with expanded connectivity range and improved findability

  • Apple introduces Digital ID

  • Apple unleashes M5 CPU and new devices

  • Apple debuts iPhone 17, Pro, Max, Air, Watch Series 11, Watch Ultra 3, Watch SE 3, AirPods Pro 3

  • Apple unveils Mac Studio featuring M4 Max and new M3 Ultra

Latest News

Arctic announces Senza AI 370 Under Desk PC for AI Applications
Consumer Electronics

Arctic announces Senza AI 370 Under Desk PC for AI Applications

CORSAIR Announces the Airflow-focused 3200D Mid Tower for Ambitious DIY PC Builds
Cooling Systems

CORSAIR Announces the Airflow-focused 3200D Mid Tower for Ambitious DIY PC Builds

Silicon Power Launches Enterprise-Grade DDR5 RDIMM to Accelerate AI Workloads
Enterprise & IT

Silicon Power Launches Enterprise-Grade DDR5 RDIMM to Accelerate AI Workloads

World Backup Day 2026: A Backup Doesn’t Always Need to be in the Cloud
Enterprise & IT

World Backup Day 2026: A Backup Doesn’t Always Need to be in the Cloud

Sharkoon announces S100 ARGB AIO Cooler
Cooling Systems

Sharkoon announces S100 ARGB AIO Cooler

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Arctic Liquid Freezer III 360 Pro Argb

Arctic Liquid Freezer III 360 Pro Argb

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed