cbcvebase.
CVE-2009-1703
published 2009-06-10

CVE-2009-1703: WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) video elements, which allows remote attackers to determine…

PriorityP429high7.1CVSS 2.0
AVNACMAuNCCINAN
EPSS
3.01%
86.0th percentile
WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) video elements, which allows remote attackers to determine the existence of arbitrary files via a crafted HTML document.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
applesafari<= 4.0_beta
applesafari<= 3.2.3
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari

CVSS provenance

nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:C/I:N/A:N
osv7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.