Lucene search

K
nvd[email protected]NVD:CVE-2009-1697
HistoryJun 10, 2009 - 6:00 p.m.

CVE-2009-1697

2009-06-1018:00:00
CWE-20
web.nvd.nist.gov
5

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.8

Confidence

High

EPSS

0.006

Percentile

78.8%

CRLF injection vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject HTTP headers and bypass the Same Origin Policy via a crafted HTML document, related to cross-site scripting (XSS) attacks that depend on communication with arbitrary web sites on the same server through use of XMLHttpRequest without a Host header.

Affected configurations

Nvd
Node
applesafariRange4.0_betamac
OR
applesafariMatch0.8mac
OR
applesafariMatch0.9mac
OR
applesafariMatch1.0mac
OR
applesafariMatch1.0.3mac
OR
applesafariMatch1.1mac
OR
applesafariMatch1.2mac
OR
applesafariMatch1.3mac
OR
applesafariMatch1.3.1mac
OR
applesafariMatch1.3.2mac
OR
applesafariMatch2.0mac
OR
applesafariMatch2.0.2mac
OR
applesafariMatch2.0.4mac
OR
applesafariMatch3.0mac
OR
applesafariMatch3.0.2-mac
OR
applesafariMatch3.0.3mac
OR
applesafariMatch3.0.4mac
OR
applesafariMatch3.1mac
OR
applesafariMatch3.1.1mac
OR
applesafariMatch3.1.2mac
OR
applesafariMatch3.2.1mac
OR
applesafariMatch3.2.3mac
Node
applesafariRange3.2.3windows
OR
applesafariMatch3.0windows
OR
applesafariMatch3.0.1windows
OR
applesafariMatch3.0.2windows
OR
applesafariMatch3.0.3windows
OR
applesafariMatch3.0.4windows
OR
applesafariMatch3.1windows
OR
applesafariMatch3.1.1windows
OR
applesafariMatch3.1.2windows
OR
applesafariMatch3.2-windows
OR
applesafariMatch3.2.1windows
OR
applesafariMatch3.2.2windows
VendorProductVersionCPE
applesafari*cpe:2.3:a:apple:safari:*:*:mac:*:*:*:*:*
applesafari0.8cpe:2.3:a:apple:safari:0.8:*:mac:*:*:*:*:*
applesafari0.9cpe:2.3:a:apple:safari:0.9:*:mac:*:*:*:*:*
applesafari1.0cpe:2.3:a:apple:safari:1.0:*:mac:*:*:*:*:*
applesafari1.0.3cpe:2.3:a:apple:safari:1.0.3:*:mac:*:*:*:*:*
applesafari1.1cpe:2.3:a:apple:safari:1.1:*:mac:*:*:*:*:*
applesafari1.2cpe:2.3:a:apple:safari:1.2:*:mac:*:*:*:*:*
applesafari1.3cpe:2.3:a:apple:safari:1.3:*:mac:*:*:*:*:*
applesafari1.3.1cpe:2.3:a:apple:safari:1.3.1:*:mac:*:*:*:*:*
applesafari1.3.2cpe:2.3:a:apple:safari:1.3.2:*:mac:*:*:*:*:*
Rows per page:
1-10 of 341

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.8

Confidence

High

EPSS

0.006

Percentile

78.8%