CVE-2009-2200Sensitive Information Exposure in Apple Safari

Severity
7.1HIGHNVD
EPSS
0.4%
top 38.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateMay 2

Description

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

CVSS vector

AV:N/AC:M/C:C/I:N/A:NExploitability: 8.6 | Impact: 6.9

Affected Packages1 packages

NVDapple/safari4.0.2+59

Patches

🔴Vulnerability Details

1
GHSA
GHSA-h983-8jqg-vmp6: WebKit in Apple Safari before 42022-05-02

💥Exploits & PoCs

3
Exploit-DB
HP LaserJet Printers - Multiple Persistent Cross-Site Scripting Vulnerabilities2009-10-07
Exploit-DB
HP Multiple LaserJet Printer - Cross-Site Scripting2009-07-04
Exploit-DB
Novell QuickFinder Server - Multiple Cross-Site Scripting Vulnerabilities2009-02-09

💬Community

1
Bugzilla
CVE-2009-2195 WebKit: buffer overflow in floating point numbers parsing2009-08-13