Click here for the Best Buy Homepage

iPhone Topsites

iPhone Rankings

Top Blogs

like what you've read, click here to give this author a higher rating at blogskinny.com


Technology Blogs
Technology Blogs
Create blog
Technology blogs
Technology Blog
Register for free widgets at www.blogskinny.com and increase your reader traffic

Check Web Rank

Etronics Brand Logo (120x90)
Bluehost Web Hosting $6.95

Buy.com
iPhone Accessories, apple iphone


120X60 Ringtones, Wallpaper, Videos... CELLWARE!
Jul
31

Impact: Visiting a malicious website may allow cross-site scripting

Description: Safari’s security model prevents JavaScript in remote web pages from modifying pages outside of their domain. A race condition in page updating combined with HTTP redirection may allow JavaScript from one page to modify a redirected page. This could allow cookies and pages to be read or arbitrarily modified. This update addresses the issue by correcting access control to window properties. Credit to Lawrence Lai, Stan Switzer, and Ed Rowe of Adobe Systems, Inc. for reporting this issue.

Impact: Viewing a maliciously crafted web page may lead to arbitrary code execution

Description: Heap buffer overflows exist in the Perl Compatible Regular Expressions (PCRE) library used by the JavaScript engine in Safari. By enticing a user to visit a maliciously crafted web page, an attacker may trigger the issue, which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript regular expressions. Credit to Charlie Miller and Jake Honoroff of Independent Security Evaluators for reporting these issues.

Impact: Visiting a malicious website may allow cross-site requests

Description:
An HTTP injection issue exists in XMLHttpRequest when serializing headers into an HTTP request. By enticing a user to visit a maliciously crafted web page, an attacker could trigger a cross-site scripting issue. This update addresses the issue by performing additional validation of header parameters. Credit to Richard Moore of Westpoint Ltd. for reporting this issue.

Impact: Look-alike characters in a URL could be used to masquerade a website

Description: The International Domain Name (IDN) support and Unicode fonts embedded in Safari could be used to create a URL which contains look-alike characters. These could be used in a malicious web site to direct the user to a spoofed site that visually appears to be a legitimate domain. This update addresses the issue by through an improved domain name validity check.

Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution

Description: An invalid type conversion when rendering frame sets could lead to memory corruption. Visiting a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution. Credit to Rhys Kidd of Westnet for reporting this issue.

TopiPhoneNews.com: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Netvouz
  • DZone
  • ThisNext
  • MisterWong
  • Wists
  • blinkbits
  • BlinkList
  • blogmarks
  • BlogMemes
  • blogtercimlap
  • Blue Dot
  • Book.mark.hu
  • Bumpzee
  • co.mments
  • connotea
  • De.lirio.us
  • DotNetKicks
  • Fark
  • feedmelinks
  • Fleck
  • Furl
  • Gwar
  • MyShare
  • Netscape
  • NewsVine
  • PopCurrent
  • Reddit
  • Simpy
  • Smarking
  • SphereIt
  • Spurl
  • StumbleUpon
  • Technorati
  • YahooMyWeb

No Comments Make A Comment

No comments yet.

Comments RSS Feed   TrackBack URL

Leave a comment

Blogroll.net Top Blog Topsites List BRDTracker Top Blog Topsites Directory Blog Review Bloggapedia, Blog Directory - Find It!
Mobile Phone Blogs - Blog Catalog Blog Directory Find Blogs in the Blog
Directory blog search directory Technology blogs Blog Flux Directory BlogBib - Blog Directory Blog Directory & Search engine
Listed in LS Blogs Romow Web Directory - Online Internet Marketing Center blogoriffic.com Outpost Blogadr.com - Listed (add your blog to Blogadr.com) Blog Directory - photarium Blogarama - The Blog Directory