Lucene search

K
cveMitreCVE-2009-2200
HistoryAug 12, 2009 - 7:30 p.m.

CVE-2009-2200

2009-08-1219:30:00
CWE-200
mitre
web.nvd.nist.gov
28
4
apple safari
webkit
cve-2009-2200
url scheme
vulnerability
nvd

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:C/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.004

Percentile

74.9%

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

Affected configurations

Nvd
Node
applemac_os_xMatch10.4.
OR
applemac_os_xMatch10.5.7
OR
applemac_os_xMatch10.5.8
OR
applemac_os_x_serverMatch10.4.11
OR
applemac_os_x_serverMatch10.5.7
OR
applemac_os_x_serverMatch10.5.8
OR
microsoftwindows_vista
OR
microsoftwindows_xp
AND
applesafariRange4.0.2
OR
applesafariMatch0.8
OR
applesafariMatch0.9
OR
applesafariMatch1.0
OR
applesafariMatch1.0beta
OR
applesafariMatch1.0beta2
OR
applesafariMatch1.0.0
OR
applesafariMatch1.0.0b1
OR
applesafariMatch1.0.0b2
OR
applesafariMatch1.0.1
OR
applesafariMatch1.0.2
OR
applesafariMatch1.0.3
OR
applesafariMatch1.0.385.8
OR
applesafariMatch1.0.385.8.1
OR
applesafariMatch1.1
OR
applesafariMatch1.1.0
OR
applesafariMatch1.1.1
OR
applesafariMatch1.2
OR
applesafariMatch1.2.0
OR
applesafariMatch1.2.1
OR
applesafariMatch1.2.2
OR
applesafariMatch1.2.3
OR
applesafariMatch1.2.4
OR
applesafariMatch1.2.5
OR
applesafariMatch1.3
OR
applesafariMatch1.3.0
OR
applesafariMatch1.3.1
OR
applesafariMatch1.3.2
OR
applesafariMatch1.3.2312.5
OR
applesafariMatch1.3.2312.6
OR
applesafariMatch2.0
OR
applesafariMatch2.0.0
OR
applesafariMatch2.0.1
OR
applesafariMatch2.0.2
OR
applesafariMatch2.0.3
OR
applesafariMatch2.0.3417.8
OR
applesafariMatch2.0.3417.9
OR
applesafariMatch2.0.3417.9.2
OR
applesafariMatch2.0.3417.9.3
OR
applesafariMatch2.0.3_417.9.3
OR
applesafariMatch2.0.4
OR
applesafariMatch2.0.4_419.3
OR
applesafariMatch2.0_pre
OR
applesafariMatch3
OR
applesafariMatch3.0
OR
applesafariMatch3.0.0
OR
applesafariMatch3.0.0b
OR
applesafariMatch3.0.1
OR
applesafariMatch3.0.1beta
OR
applesafariMatch3.0.1b
OR
applesafariMatch3.0.2
OR
applesafariMatch3.0.2b
OR
applesafariMatch3.0.3
OR
applesafariMatch3.0.3522.15.5
OR
applesafariMatch3.0.3b
OR
applesafariMatch3.0.4
OR
applesafariMatch3.0.4_beta
OR
applesafariMatch3.0.4b
OR
applesafariMatch3.1
OR
applesafariMatch3.1.0
OR
applesafariMatch3.1.0b
OR
applesafariMatch3.1.1
OR
applesafariMatch3.1.2
OR
applesafariMatch3.2
OR
applesafariMatch3.2.0
OR
applesafariMatch3.2.1
OR
applesafariMatch3.2.2
OR
applesafariMatch4.0
OR
applesafariMatch4.0beta
OR
applesafariMatch4.0.1
OR
applesafariMatch4.0_beta528.16
OR
applesafariMatch4beta
OR
applesafariMatchbeta2
VendorProductVersionCPE
applesafari1.2.2cpe:/a:apple:safari:1.2.2:::
applesafari3.0.3bcpe:/a:apple:safari:3.0.3b:::
applesafari3.2.1cpe:/a:apple:safari:3.2.1:::
applesafaribeta2cpe:/a:apple:safari:beta2:::
applesafari3.0.1cpe:/a:apple:safari:3.0.1:::
applesafari3.1.0bcpe:/a:apple:safari:3.1.0b:::
applesafari1.1.0cpe:/a:apple:safari:1.1.0:::
applesafari3.0.1bcpe:/a:apple:safari:3.0.1b:::
applesafari3.0.3cpe:/a:apple:safari:3.0.3:::
applesafari1.0.0b2cpe:/a:apple:safari:1.0.0b2:::
Rows per page:
1-10 of 731

Social References

More

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:C/I:N/A:N

AI Score

7.5

Confidence

High

EPSS

0.004

Percentile

74.9%