Lucene search

K
ubuntucveUbuntu.comUB:CVE-2009-1681
HistoryJun 10, 2009 - 12:00 a.m.

CVE-2009-1681

2009-06-1000:00:00
ubuntu.com
ubuntu.com
12

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.006

Percentile

77.7%

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone
OS for iPod touch 1.1 through 2.2.1 does not prevent web sites from loading
third-party content into a subframe, which allows remote attackers to
bypass the Same Origin Policy and conduct “clickjacking” attacks via a
crafted HTML document.

Bugs

Notes

Author Note
jdstrand webkit is a fork of khtml from kdelibs. kdelibs5 is farther from it, while qt4-x11 attempts to unify khtml and webkit
mdeslaur code doesn’t seem present in kdelibs. this code implements X-FRAME-OPTIONS (in ie8, not in firefox) this is new functionality

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.006

Percentile

77.7%