Lucene search

K
prionPRIOn knowledge basePRION:CVE-2009-1699
HistoryJun 10, 2009 - 6:00 p.m.

Design/Logic Flaw

2009-06-1018:00:00
PRIOn knowledge base
www.prio-n.com
5

6.6 Medium

AI Score

Confidence

Low

0.031 Low

EPSS

Percentile

91.1%

The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an “XXE attack.”

6.6 Medium

AI Score

Confidence

Low

0.031 Low

EPSS

Percentile

91.1%