CVE-2009-1700
published 2009-06-10CVE-2009-1700: The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.62%
83.9th percentile
The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read XML content from arbitrary web pages via a crafted document.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | safari | <= 3.2.2 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4hwh-c92m-9mrx: The XSLT implementation in WebKit in Apple Safari before 4
ghsa_unreviewed·2022-05-02
CVE-2009-1700 [MEDIUM] CWE-200 GHSA-4hwh-c92m-9mrx: The XSLT implementation in WebKit in Apple Safari before 4
The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read XML content from arbitrary web pages via a crafted document.
OSV
CVE-2009-1700: The XSLT implementation in WebKit in Apple Safari before 4
osv·2009-06-10·CVSS 4.3
CVE-2009-1700 [MEDIUM] CVE-2009-1700: The XSLT implementation in WebKit in Apple Safari before 4
The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read XML content from arbitrary web pages via a crafted document.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://osvdb.org/54973http://secunia.com/advisories/35379http://secunia.com/advisories/43068http://support.apple.com/kb/HT3613http://support.apple.com/kb/HT3639http://www.securityfocus.com/bid/35260http://www.vupen.com/english/advisories/2009/1522http://www.vupen.com/english/advisories/2009/1621http://www.vupen.com/english/advisories/2011/0212http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://osvdb.org/54973http://secunia.com/advisories/35379http://secunia.com/advisories/43068http://support.apple.com/kb/HT3613http://support.apple.com/kb/HT3639http://www.securityfocus.com/bid/35260http://www.vupen.com/english/advisories/2009/1522http://www.vupen.com/english/advisories/2009/1621http://www.vupen.com/english/advisories/2011/0212
2009-06-10
Published