Lucene search

K
cveMitreCVE-2009-3455
HistorySep 29, 2009 - 6:00 p.m.

CVE-2009-3455

2009-09-2918:00:00
CWE-310
mitre
web.nvd.nist.gov
42
apple safari
mac os x
ssl servers
x.509 certificate
man-in-the-middle
cve-2009-3455
cve-2009-2408

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

5.7

Confidence

High

EPSS

0.003

Percentile

65.3%

Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a ‘\0’ character in a domain name in the subject’s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Affected configurations

Nvd
Node
applesafariRange4.0.2-mac
OR
applesafariMatch0.8-mac
OR
applesafariMatch0.9-mac
OR
applesafariMatch1.0-mac
OR
applesafariMatch1.0.0-mac
OR
applesafariMatch1.0b1-mac
OR
applesafariMatch1.1-mac
OR
applesafariMatch1.2-mac
OR
applesafariMatch1.2.0-mac
OR
applesafariMatch1.2.1-mac
OR
applesafariMatch1.2.2-mac
OR
applesafariMatch1.2.3-mac
OR
applesafariMatch1.2.4-mac
OR
applesafariMatch1.2.5-mac
OR
applesafariMatch1.3-mac
OR
applesafariMatch1.3.1-mac
OR
applesafariMatch1.3.2-mac
OR
applesafariMatch2.0-mac
OR
applesafariMatch2.0.0-mac
OR
applesafariMatch2.0.1-mac
OR
applesafariMatch2.0.2-mac
OR
applesafariMatch2.0.3-mac
OR
applesafariMatch2.0.4-mac
OR
applesafariMatch3.0mac
OR
applesafariMatch3.0-mac
OR
applesafariMatch3.0.0-mac
OR
applesafariMatch3.0.1-mac
OR
applesafariMatch3.0.3mac
OR
applesafariMatch3.0.3-mac
OR
applesafariMatch3.0.4mac
OR
applesafariMatch3.0.4-mac
OR
applesafariMatch3.1mac
OR
applesafariMatch3.1-mac
OR
applesafariMatch3.1.0-mac
OR
applesafariMatch3.1.1mac
OR
applesafariMatch3.1.1-mac
OR
applesafariMatch3.1.2mac
OR
applesafariMatch3.1.2-mac
OR
applesafariMatch3.2-mac
OR
applesafariMatch3.2.1mac
OR
applesafariMatch3.2.1-mac
OR
applesafariMatch3.2.3mac
OR
applesafariMatch3.2.3-mac
OR
applesafariMatch4.0-mac
OR
applesafariMatch4.0.0b-mac
OR
applesafariMatch4.0.1-mac
OR
applesafariMatch4.0.2mac
OR
applesafariMatch4.0_beta-mac
VendorProductVersionCPE
applesafari*cpe:2.3:a:apple:safari:*:-:mac:*:*:*:*:*
applesafari0.8cpe:2.3:a:apple:safari:0.8:-:mac:*:*:*:*:*
applesafari0.9cpe:2.3:a:apple:safari:0.9:-:mac:*:*:*:*:*
applesafari1.0cpe:2.3:a:apple:safari:1.0:-:mac:*:*:*:*:*
applesafari1.0.0cpe:2.3:a:apple:safari:1.0.0:-:mac:*:*:*:*:*
applesafari1.0b1cpe:2.3:a:apple:safari:1.0b1:-:mac:*:*:*:*:*
applesafari1.1cpe:2.3:a:apple:safari:1.1:-:mac:*:*:*:*:*
applesafari1.2cpe:2.3:a:apple:safari:1.2:-:mac:*:*:*:*:*
applesafari1.2.0cpe:2.3:a:apple:safari:1.2.0:-:mac:*:*:*:*:*
applesafari1.2.1cpe:2.3:a:apple:safari:1.2.1:-:mac:*:*:*:*:*
Rows per page:
1-10 of 481

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

5.7

Confidence

High

EPSS

0.003

Percentile

65.3%