CVE-2009-1703 — Sensitive Information Exposure in Apple Safari
Severity
7.1HIGHNVD
NVD5.8
EPSS
0.9%
top 24.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 10
Latest updateMay 2
Description
WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) video elements, which allows remote attackers to determine the existence of arbitrary files via a crafted HTML document.
CVSS vector
AV:N/AC:M/C:C/I:N/A:NExploitability: 8.6 | Impact: 6.9