Lucene search

K
cveMitreCVE-2009-1714
HistoryJun 10, 2009 - 6:00 p.m.

CVE-2009-1714

2009-06-1018:00:00
CWE-79
mitre
web.nvd.nist.gov
45
cve-2009-1714
cross-site scripting
xss
webkit
apple safari
remote code execution

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

High

EPSS

0.003

Percentile

70.1%

Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to the improper escaping of HTML attributes.

Affected configurations

Nvd
Node
applesafariRange4.0_beta-mac
OR
applesafariMatch0.8-mac
OR
applesafariMatch0.9-mac
OR
applesafariMatch1.0-mac
OR
applesafariMatch1.0.3-mac
OR
applesafariMatch1.1-mac
OR
applesafariMatch1.2-mac
OR
applesafariMatch1.3-mac
OR
applesafariMatch1.3.1-mac
OR
applesafariMatch1.3.2-mac
OR
applesafariMatch2.0-mac
OR
applesafariMatch2.0.2-mac
OR
applesafariMatch2.0.4-mac
OR
applesafariMatch3.0-mac
OR
applesafariMatch3.0.2-mac
OR
applesafariMatch3.0.3-mac
OR
applesafariMatch3.0.4-mac
OR
applesafariMatch3.1-mac
OR
applesafariMatch3.1.1-mac
OR
applesafariMatch3.1.2-mac
OR
applesafariMatch3.2.1-mac
OR
applesafariMatch3.2.3-mac
Node
applesafariRange3.2.3-windows
OR
applesafariMatch3.0-windows
OR
applesafariMatch3.0.1-windows
OR
applesafariMatch3.0.2-windows
OR
applesafariMatch3.0.3-windows
OR
applesafariMatch3.0.4-windows
OR
applesafariMatch3.1-windows
OR
applesafariMatch3.1.1-windows
OR
applesafariMatch3.1.2-windows
OR
applesafariMatch3.2-windows
OR
applesafariMatch3.2.1-windows
OR
applesafariMatch3.2.2-windows
VendorProductVersionCPE
applesafari*cpe:2.3:a:apple:safari:*:-:mac:*:*:*:*:*
applesafari0.8cpe:2.3:a:apple:safari:0.8:-:mac:*:*:*:*:*
applesafari0.9cpe:2.3:a:apple:safari:0.9:-:mac:*:*:*:*:*
applesafari1.0cpe:2.3:a:apple:safari:1.0:-:mac:*:*:*:*:*
applesafari1.0.3cpe:2.3:a:apple:safari:1.0.3:-:mac:*:*:*:*:*
applesafari1.1cpe:2.3:a:apple:safari:1.1:-:mac:*:*:*:*:*
applesafari1.2cpe:2.3:a:apple:safari:1.2:-:mac:*:*:*:*:*
applesafari1.3cpe:2.3:a:apple:safari:1.3:-:mac:*:*:*:*:*
applesafari1.3.1cpe:2.3:a:apple:safari:1.3.1:-:mac:*:*:*:*:*
applesafari1.3.2cpe:2.3:a:apple:safari:1.3.2:-:mac:*:*:*:*:*
Rows per page:
1-10 of 341

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

High

EPSS

0.003

Percentile

70.1%