CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:N/I:P/A:N
AI Score
Confidence
High
EPSS
Percentile
95.3%
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via an event handler that triggers script execution in the context of the next loaded document.
Vendor | Product | Version | CPE |
---|---|---|---|
apple | safari | * | cpe:2.3:a:apple:safari:*:*:mac:*:*:*:*:* |
apple | safari | 0.8 | cpe:2.3:a:apple:safari:0.8:*:mac:*:*:*:*:* |
apple | safari | 0.9 | cpe:2.3:a:apple:safari:0.9:*:mac:*:*:*:*:* |
apple | safari | 1.0 | cpe:2.3:a:apple:safari:1.0:*:mac:*:*:*:*:* |
apple | safari | 1.0.3 | cpe:2.3:a:apple:safari:1.0.3:*:mac:*:*:*:*:* |
apple | safari | 1.1 | cpe:2.3:a:apple:safari:1.1:*:mac:*:*:*:*:* |
apple | safari | 1.2 | cpe:2.3:a:apple:safari:1.2:*:mac:*:*:*:*:* |
apple | safari | 1.3 | cpe:2.3:a:apple:safari:1.3:*:mac:*:*:*:*:* |
apple | safari | 1.3.1 | cpe:2.3:a:apple:safari:1.3.1:*:mac:*:*:*:*:* |
apple | safari | 1.3.2 | cpe:2.3:a:apple:safari:1.3.2:*:mac:*:*:*:*:* |
lists.apple.com/archives/security-announce/2009/jun/msg00002.html
lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
osvdb.org/54987
secunia.com/advisories/35379
secunia.com/advisories/37746
secunia.com/advisories/43068
securitytracker.com/id?1022344
support.apple.com/kb/HT3613
support.apple.com/kb/HT3639
www.debian.org/security/2009/dsa-1950
www.securityfocus.com/bid/35260
www.vupen.com/english/advisories/2009/1522
www.vupen.com/english/advisories/2009/1621
www.vupen.com/english/advisories/2011/0212