CVE-2009-1713
published 2009-06-10CVE-2009-1713: The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1)…
PriorityP429high7.1CVSS 2.0
AVNACMAuNCCINAN
EPSS
2.05%
79.3th percentile
The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 4.0_beta | — |
| apple | safari | <= 3.2.3 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:C/I:N/A:N
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2x3g-6456-c8h3: The XSLT functionality in WebKit in Apple Safari before 4
ghsa_unreviewed·2022-05-02
CVE-2009-1713 [HIGH] CWE-200 GHSA-2x3g-6456-c8h3: The XSLT functionality in WebKit in Apple Safari before 4
The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors.
Ubuntu
Qt vulnerabilities
vendor_ubuntu·2009-11-10·CVSS 9.3
CVE-2009-1699 [CRITICAL] Qt vulnerabilities
Title: Qt vulnerabilities
Summary: Qt vulnerabilities
It was discovered that QtWebKit did not properly handle certain SVGPathList
data structures. If a user were tricked into viewing a malicious website,
an attacker could exploit this to execute arbitrary code with the
privileges of the user invoking the program. (CVE-2009-0945)
Several flaws were discovered in the QtWebKit browser and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could cause a denial of service or possibly execute arbitrary code
with the privileges of the user invoking the program. (CVE-2009-1687,
CVE-2009-1690, CVE-2009-1698, CVE-2009-1711, CVE-2009-1725)
It was discovered that QtWebKit did not properly handle certain XSL
stylesheets. If a user were tricked into viewin
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://osvdb.org/54975http://secunia.com/advisories/35379http://secunia.com/advisories/43068http://support.apple.com/kb/HT3613http://www.securityfocus.com/bid/35260http://www.ubuntu.com/usn/USN-857-1http://www.vupen.com/english/advisories/2009/1522http://www.vupen.com/english/advisories/2011/0212https://exchange.xforce.ibmcloud.com/vulnerabilities/51267http://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://osvdb.org/54975http://secunia.com/advisories/35379http://secunia.com/advisories/43068http://support.apple.com/kb/HT3613http://www.securityfocus.com/bid/35260http://www.ubuntu.com/usn/USN-857-1http://www.vupen.com/english/advisories/2009/1522http://www.vupen.com/english/advisories/2011/0212https://exchange.xforce.ibmcloud.com/vulnerabilities/51267
2009-06-10
Published