Lucene search

K
cve[email protected]CVE-2009-1700
HistoryJun 10, 2009 - 6:00 p.m.

CVE-2009-1700

2009-06-1018:00:00
CWE-200
web.nvd.nist.gov
29
cve-2009-1700
xslt
webkit
apple safari
iphone os
security vulnerability
xml content
remote attack

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7.6 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.1%

The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read XML content from arbitrary web pages via a crafted document.

Affected configurations

NVD
Node
applesafariRange3.2.2
OR
applesafariMatch2.0
OR
applesafariMatch2.0.0
OR
applesafariMatch2.0.1
OR
applesafariMatch2.0.2
OR
applesafariMatch2.0.3
OR
applesafariMatch2.0.3417.8
OR
applesafariMatch2.0.3417.9
OR
applesafariMatch2.0.3417.9.2
OR
applesafariMatch2.0.3417.9.3
OR
applesafariMatch2.0.4
OR
applesafariMatch3.0
OR
applesafariMatch3.0.0
OR
applesafariMatch3.0.0b
OR
applesafariMatch3.0.1
OR
applesafariMatch3.0.1beta
OR
applesafariMatch3.0.1b
OR
applesafariMatch3.0.2
OR
applesafariMatch3.0.2b
OR
applesafariMatch3.0.3
OR
applesafariMatch3.0.3b
OR
applesafariMatch3.0.4
OR
applesafariMatch3.0.4b
OR
applesafariMatch3.1.0
OR
applesafariMatch3.1.0b
OR
applesafariMatch3.1.1
OR
applesafariMatch3.1.2
OR
applesafariMatch3.2.0
OR
applesafariMatch3.2.1
Node
appleiphone_osMatch1.0.0
OR
appleiphone_osMatch1.0.1
OR
appleiphone_osMatch1.0.2
OR
appleiphone_osMatch1.1.0
OR
appleiphone_osMatch1.1.1
OR
appleiphone_osMatch1.1.2
OR
appleiphone_osMatch1.1.3
OR
appleiphone_osMatch1.1.4
OR
appleiphone_osMatch1.1.5
OR
appleiphone_osMatch2.0
OR
appleiphone_osMatch2.0.0
OR
appleiphone_osMatch2.0.1
OR
appleiphone_osMatch2.0.2
OR
appleiphone_osMatch2.1
OR
appleiphone_osMatch2.1.1
OR
appleiphone_osMatch2.2
OR
appleiphone_osMatch2.2.1
AND
appleipod_touch
OR
appleiphone_os

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

7.6 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.1%