Lucene search

K
cveMitreCVE-2009-2066
HistoryJun 15, 2009 - 7:30 p.m.

CVE-2009-2066

2009-06-1519:30:05
CWE-287
mitre
web.nvd.nist.gov
25
apple
safari
vulnerability
cve-2009-2066
man-in-the-middle
http
https
web script
security
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.002

Percentile

54.7%

Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https siteโ€™s context, by modifying an http page to include an https iframe that references a script file on an http site, related to โ€œHTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages.โ€

Affected configurations

Nvd
Node
applesafariRangeโ‰ค3.2.1
OR
applesafariMatch0.8
OR
applesafariMatch0.9
OR
applesafariMatch1.0
OR
applesafariMatch1.0beta
OR
applesafariMatch1.0beta2
OR
applesafariMatch1.0.0
OR
applesafariMatch1.0.0b1
OR
applesafariMatch1.0.0b2
OR
applesafariMatch1.0.1
OR
applesafariMatch1.0.2
OR
applesafariMatch1.0.3
OR
applesafariMatch1.0.385.8
OR
applesafariMatch1.0.385.8.1
OR
applesafariMatch1.1
OR
applesafariMatch1.1.0
OR
applesafariMatch1.1.1
OR
applesafariMatch1.2
OR
applesafariMatch1.2.0
OR
applesafariMatch1.2.1
OR
applesafariMatch1.2.2
OR
applesafariMatch1.2.3
OR
applesafariMatch1.2.4
OR
applesafariMatch1.2.5
OR
applesafariMatch1.3
OR
applesafariMatch1.3.0
OR
applesafariMatch1.3.1
OR
applesafariMatch1.3.2
OR
applesafariMatch1.3.2312.5
OR
applesafariMatch1.3.2312.6
OR
applesafariMatch2
OR
applesafariMatch2.0
OR
applesafariMatch2.0.0
OR
applesafariMatch2.0.1
OR
applesafariMatch2.0.2
OR
applesafariMatch2.0.3
OR
applesafariMatch2.0.3417.8
OR
applesafariMatch2.0.3417.9
OR
applesafariMatch2.0.3417.9.2
OR
applesafariMatch2.0.3417.9.3
OR
applesafariMatch2.0.3_417.9.3
OR
applesafariMatch2.0.4
OR
applesafariMatch2.0.4_419.3
OR
applesafariMatch2.0_pre
OR
applesafariMatch3
OR
applesafariMatch3.0
OR
applesafariMatch3.0.0
OR
applesafariMatch3.0.0b
OR
applesafariMatch3.0.1
OR
applesafariMatch3.0.1beta
OR
applesafariMatch3.0.1b
OR
applesafariMatch3.0.2
OR
applesafariMatch3.0.2b
OR
applesafariMatch3.0.3
OR
applesafariMatch3.0.3522.15.5
OR
applesafariMatch3.0.3b
OR
applesafariMatch3.0.4
OR
applesafariMatch3.0.4_beta
OR
applesafariMatch3.0.4b
OR
applesafariMatch3.1
OR
applesafariMatch3.1.0
OR
applesafariMatch3.1.0b
OR
applesafariMatch3.1.1
OR
applesafariMatch3.1.2
OR
applesafariMatch3.2
OR
applesafariMatch3.2.0
VendorProductVersionCPE
applesafari*cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
applesafari0.8cpe:2.3:a:apple:safari:0.8:*:*:*:*:*:*:*
applesafari0.9cpe:2.3:a:apple:safari:0.9:*:*:*:*:*:*:*
applesafari1.0cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:*
applesafari1.0cpe:2.3:a:apple:safari:1.0:beta:*:*:*:*:*:*
applesafari1.0cpe:2.3:a:apple:safari:1.0:beta2:*:*:*:*:*:*
applesafari1.0.0cpe:2.3:a:apple:safari:1.0.0:*:*:*:*:*:*:*
applesafari1.0.0b1cpe:2.3:a:apple:safari:1.0.0b1:*:*:*:*:*:*:*
applesafari1.0.0b2cpe:2.3:a:apple:safari:1.0.0b2:*:*:*:*:*:*:*
applesafari1.0.1cpe:2.3:a:apple:safari:1.0.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 661

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.6

Confidence

Low

EPSS

0.002

Percentile

54.7%

Related for CVE-2009-2066