cbcvebase.
CVE-2009-1713
published 2009-06-10

CVE-2009-1713: The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1)…

PriorityP429high7.1CVSS 2.0
AVNACMAuNCCINAN
EPSS
2.05%
79.3th percentile
The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
applesafari<= 4.0_beta
applesafari<= 3.2.3
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari
applesafari

CVSS provenance

nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:C/I:N/A:N
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.