CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:P/A:P
AI Score
Confidence
High
EPSS
Percentile
77.4%
Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified homoglyphs.
Vendor | Product | Version | CPE |
---|---|---|---|
apple | safari | * | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* |
apple | safari | 2.0 | cpe:2.3:a:apple:safari:2.0:*:*:*:*:*:*:* |
apple | safari | 2.0.0 | cpe:2.3:a:apple:safari:2.0.0:*:*:*:*:*:*:* |
apple | safari | 2.0.1 | cpe:2.3:a:apple:safari:2.0.1:*:*:*:*:*:*:* |
apple | safari | 2.0.2 | cpe:2.3:a:apple:safari:2.0.2:*:*:*:*:*:*:* |
apple | safari | 2.0.3 | cpe:2.3:a:apple:safari:2.0.3:*:*:*:*:*:*:* |
apple | safari | 2.0.3 | cpe:2.3:a:apple:safari:2.0.3:417.8:*:*:*:*:*:* |
apple | safari | 2.0.3 | cpe:2.3:a:apple:safari:2.0.3:417.9:*:*:*:*:*:* |
apple | safari | 2.0.3 | cpe:2.3:a:apple:safari:2.0.3:417.9.2:*:*:*:*:*:* |
apple | safari | 2.0.3 | cpe:2.3:a:apple:safari:2.0.3:417.9.3:*:*:*:*:*:* |
lists.apple.com/archives/security-announce/2009/Aug/msg00002.html
lists.apple.com/archives/security-announce/2009/Sep/msg00001.html
lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
secunia.com/advisories/36677
secunia.com/advisories/43068
support.apple.com/kb/HT3733
support.apple.com/kb/HT3860
www.securityfocus.com/bid/36026
www.securitytracker.com/id?1022719
www.vupen.com/english/advisories/2011/0212
More