Vulnerability Name: | CVE-2009-1696 |
Assigned: | 2009-06-10 |
Published: | 2009-06-10 |
Updated: | 2011-02-17 |
Summary: | WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 uses predictable random numbers in JavaScript applications, which makes it easier for remote web servers to track the behavior of a Safari user during a session.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None |
|
Vulnerability Type: | CWE-310
|
References: | Source: MITRE Type: CNA CVE-2009-1696
Source: APPLE Type: Patch, Vendor Advisory APPLE-SA-2009-06-08-1
Source: APPLE Type: UNKNOWN APPLE-SA-2009-06-17-1
Source: SUSE Type: UNKNOWN SUSE-SR:2011:002
Source: OSVDB Type: UNKNOWN 55027
Source: SECUNIA Type: Vendor Advisory 35379
Source: SECUNIA Type: UNKNOWN 43068
Source: CONFIRM Type: Patch, Vendor Advisory http://support.apple.com/kb/HT3613
Source: CONFIRM Type: UNKNOWN http://support.apple.com/kb/HT3639
Source: BID Type: Exploit 35260
Source: VUPEN Type: Patch, Vendor Advisory ADV-2009-1522
Source: VUPEN Type: UNKNOWN ADV-2009-1621
Source: VUPEN Type: UNKNOWN ADV-2011-0212
|
Vulnerable Configuration: | Configuration 1: cpe:/a:apple:safari:0.8:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:0.9:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.0:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.0.3:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.2:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.3:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.3.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.3.2:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:2.0:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:2.0.2:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:2.0.4:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.0:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.0.2:-:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.0.3:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.0.4:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.1.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.1.2:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.2.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.2.3:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:*:*:mac:*:*:*:*:* (Version <= 4.0_beta) Configuration 2: cpe:/a:apple:safari:3.0:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.0.1:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.0.2:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.0.3:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.0.4:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.1:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.1.1:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.1.2:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.2:-:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.2.1:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.2.2:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:*:*:windows:*:*:*:*:* (Version <= 3.2.3)
Denotes that component is vulnerable |
Oval Definitions |
|
BACK |