Vulnerability Name: | CVE-2009-1684 (CCN-51229) |
Assigned: | 2009-06-08 |
Published: | 2009-06-08 |
Updated: | 2011-02-17 |
Summary: | Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via an event handler that triggers script execution in the context of the next loaded document.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): None | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-79
|
Vulnerability Consequences: | Gain Access |
References: | Source: MITRE Type: CNA CVE-2009-1684
Source: APPLE Type: Patch, Vendor Advisory APPLE-SA-2009-06-08-1
Source: APPLE Type: UNKNOWN APPLE-SA-2009-06-17-1
Source: SUSE Type: UNKNOWN SUSE-SR:2011:002
Source: OSVDB Type: UNKNOWN 54987
Source: CCN Type: SA35379 Apple Safari Multiple Vulnerabilities
Source: SECUNIA Type: Vendor Advisory 35379
Source: SECUNIA Type: UNKNOWN 37746
Source: SECUNIA Type: UNKNOWN 43068
Source: CCN Type: SECTRACK ID: 1022344 Apple Safari Bugs Permit Cross-Domain Scripting Attacks
Source: SECTRACK Type: Patch 1022344
Source: CCN Type: Apple Web site About the security content of Safari 4.0
Source: CONFIRM Type: Patch, Vendor Advisory http://support.apple.com/kb/HT3613
Source: CONFIRM Type: UNKNOWN http://support.apple.com/kb/HT3639
Source: DEBIAN Type: UNKNOWN DSA-1950
Source: DEBIAN Type: DSA-1950 webkit -- several vulnerabilities
Source: CCN Type: OSVDB ID: 54987 Apple Safari WebKit JavaScript Context Splitting Event Handler Subsequent Frame XSS
Source: BID Type: Exploit 35260
Source: CCN Type: BID-35260 RETIRED: Apple Safari Prior to 4.0 Multiple Security Vulnerabilities
Source: CCN Type: BID-35315 WebKit JavaScript 'onload()' Event Cross Domain Scripting Vulnerability
Source: CCN Type: BID-35346 Apple Safari for Windows Private Browsing Cookie Data Local Information Disclosure Vulnerability
Source: VUPEN Type: Patch, Vendor Advisory ADV-2009-1522
Source: VUPEN Type: UNKNOWN ADV-2009-1621
Source: VUPEN Type: UNKNOWN ADV-2011-0212
Source: XF Type: UNKNOWN safari-eventhandler-xss(51229)
Source: SUSE Type: SUSE-SR:2011:002 SUSE Security Summary Report
|
Vulnerable Configuration: | Configuration 1: cpe:/a:apple:safari:0.8:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:0.9:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.0:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.0.3:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.2:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.3:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.3.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.3.2:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:2.0:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:2.0.2:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:2.0.4:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.0:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.0.2:-:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.0.3:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.0.4:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.1.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.1.2:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.2.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.2.3:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:*:*:mac:*:*:*:*:* (Version <= 4.0_beta) Configuration 2: cpe:/a:apple:safari:3.0:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.0.1:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.0.2:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.0.3:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.0.4:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.1:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.1.1:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.1.2:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.2:-:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.2.1:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.2.2:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:*:*:windows:*:*:*:*:* (Version <= 3.2.3) Configuration CCN 1: cpe:/a:apple:safari:2.0.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.3:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:1.3.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:1.3:*:*:*:*:*:*:*OR cpe:/a:apple:safari:1.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:1.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:1.0:*:*:*:*:*:*:*OR cpe:/a:apple:safari:2.0:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.4:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.1.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.1.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.2.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.2.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:1.0.3:*:*:*:*:*:*:*OR cpe:/a:apple:safari:1.3.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:0.8:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.2.3:*:*:*:*:*:*:*OR cpe:/a:apple:safari:4.0:beta:*:*:*:*:*:*OR cpe:/a:apple:safari:0.9:*:*:*:*:*:*:*AND cpe:/o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*OR cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x:10.5.7:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x_server:10.5.7:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |