Vulnerability Name: | CVE-2009-1704 (CCN-51220) |
Assigned: | 2009-06-08 |
Published: | 2009-06-08 |
Updated: | 2009-06-19 |
Summary: | CFNetwork in Apple Safari before 4.0 misinterprets downloaded image files as local HTML documents in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript code by placing it in an image file.
|
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): Low |
|
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Authentication (Au): None | Impact Metrics: | Confidentiality (C): Complete Integrity (I): Complete Availibility (A): Complete | 6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial |
|
Vulnerability Type: | CWE-94
|
Vulnerability Consequences: | Gain Access |
References: | Source: MITRE Type: CNA CVE-2009-1704
Source: APPLE Type: Patch, Vendor Advisory APPLE-SA-2009-06-08-1
Source: OSVDB Type: UNKNOWN 55010
Source: CCN Type: SA35379 Apple Safari Multiple Vulnerabilities
Source: SECUNIA Type: Vendor Advisory 35379
Source: CCN Type: SECTRACK ID: 1022343 Apple Safari Lets Remote Users Execute Arbitrary JavaScript in the Local Context
Source: SECTRACK Type: Patch 1022343
Source: CCN Type: Apple Web site About the security content of Safari 4.0
Source: CONFIRM Type: Patch, Vendor Advisory http://support.apple.com/kb/HT3613
Source: CCN Type: OSVDB ID: 55010 Apple Safari CFNetwork Image File Content Type Handling XSS
Source: BID Type: Exploit 35260
Source: CCN Type: BID-35260 RETIRED: Apple Safari Prior to 4.0 Multiple Security Vulnerabilities
Source: BID Type: UNKNOWN 35344
Source: CCN Type: BID-35344 Apple Safari CFNetwork Script Injection Weakness
Source: VUPEN Type: Patch, Vendor Advisory ADV-2009-1522
Source: XF Type: UNKNOWN safari-cfnetwork-code-execution(51220)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:apple:safari:0.8:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:0.9:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.0:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.0.3:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.2:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.3:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.3.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.3.2:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:2.0:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:2.0.2:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:2.0.4:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.0:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.0.2:-:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.0.3:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.0.4:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.1.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.1.2:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.2.1:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:3.2.3:*:mac:*:*:*:*:*OR cpe:/a:apple:safari:*:*:mac:*:*:*:*:* (Version <= 4.0_beta) Configuration 2: cpe:/a:apple:safari:3.0:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.0.1:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.0.2:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.0.3:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.0.4:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.1:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.1.1:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.1.2:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.2:-:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.2.1:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:3.2.2:*:windows:*:*:*:*:*OR cpe:/a:apple:safari:*:*:windows:*:*:*:*:* (Version <= 3.2.3) Configuration CCN 1: cpe:/a:apple:safari:2.0.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:2.0.4:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.3:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:1.3.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:1.3:*:*:*:*:*:*:*OR cpe:/a:apple:safari:1.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:1.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:1.0:*:*:*:*:*:*:*OR cpe:/a:apple:safari:2.0:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.4:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.1.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.1.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.2.1:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.2.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.0.2:-:mac:*:*:*:*:*OR cpe:/a:apple:safari:1.0.3:*:*:*:*:*:*:*OR cpe:/a:apple:safari:1.3.2:*:*:*:*:*:*:*OR cpe:/a:apple:safari:0.8:*:*:*:*:*:*:*OR cpe:/a:apple:safari:3.2.3:*:*:*:*:*:*:*OR cpe:/a:apple:safari:4.0:beta:*:*:*:*:*:*OR cpe:/a:apple:safari:0.9:*:*:*:*:*:*:*AND cpe:/o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x:10.5.7:*:*:*:*:*:*:*OR cpe:/o:apple:mac_os_x_server:10.5.7:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |