AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-1687

HIGH · CVSS 9.3 EPSS 8.11%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-06-10 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 9.3. It affects Java. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2009-1687
Severity
HIGH
CVSS
9.3
EPSS
8.11%
Java

Original NVD Description

The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle allocation failures, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document that triggers write access to an "offset of a NULL pointer."