9.3 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
0.036 Low
EPSS
Percentile
91.6%
WebKit in Apple Safari before 4.0 does not prevent remote loading of local
Java applets, which allows remote attackers to execute arbitrary code, gain
privileges, or obtain sensitive information via an APPLET or OBJECT
element.
Author | Note |
---|---|
jdstrand | webkit is a fork of khtml from kdelibs. kdelibs5 is farther from it, while qt4-x11 attempts to unify khtml and webkit |
mdeslaur | code does not appear present in kde4libs |