CVE-2009-1703Sensitive Information Exposure in Apple Safari

Severity
7.1HIGHNVD
NVD5.8
EPSS
0.9%
top 24.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 10
Latest updateMay 2

Description

WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) video elements, which allows remote attackers to determine the existence of arbitrary files via a crafted HTML document.

CVSS vector

AV:N/AC:M/C:C/I:N/A:NExploitability: 8.6 | Impact: 6.9

Affected Packages1 packages

NVDapple/safari4.0_beta+25

Patches

🔴Vulnerability Details

3
GHSA
GHSA-vc59-w22h-6chj: Apple Safari 32022-05-02
GHSA
GHSA-g4cv-h327-hxr6: WebKit in Apple Safari before 42022-05-02
OSV
CVE-2009-1703: WebKit in Apple Safari before 42009-06-10