CVE-2009-2200 — Sensitive Information Exposure in Apple Safari
Severity
7.1HIGHNVD
EPSS
0.4%
top 38.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateMay 2
Description
WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.
CVSS vector
AV:N/AC:M/C:C/I:N/A:NExploitability: 8.6 | Impact: 6.9