>> Apple Mac OS X KHTMLParser Remote Command Execution Vulnerability
Title : Apple Mac OS X KHTMLParser Remote Command Execution Vulnerability VUPEN ID : VUPEN/ADV-2005-3058 CVE ID : CVE-2005-4504
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-22
Technical Description
A vulnerability has been identified in Apple Mac OS X, which could be exploited by remote attackers to cause a denial of service or execute arbitrary commands. This flaw is due to heap overflow error in the KHTMLParser that does not properly handle specially crafted HTML documents, which could be exploited by remote attackers to crash an affected application (e.g. TextEdit or Safari) or compromise a vulnerable system via a malicious web page.