CVE-2009-1704Code Injection in Apple Safari

CWE-94Code Injection2 documents2 sources
Severity
9.3CRITICALNVD
EPSS
2.4%
top 15.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 10
Latest updateMay 2

Description

CFNetwork in Apple Safari before 4.0 misinterprets downloaded image files as local HTML documents in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript code by placing it in an image file.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

NVDapple/safari4.0_beta+25

Patches

🔴Vulnerability Details

1
GHSA
GHSA-v4mv-7crp-f7p6: CFNetwork in Apple Safari before 42022-05-02