CVE-2012-3713Apple Safari vulnerability

CWE-2642 documents2 sources
Severity
4.3MEDIUMNVD
EPSS
0.4%
top 37.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 20
Latest updateMay 17

Description

Apple Safari before 6.0.1 does not properly handle the Quarantine attribute of HTML documents, which allows user-assisted remote attackers to read arbitrary files by leveraging the presence of a downloaded document.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDapple/safari6.0+77

🔴Vulnerability Details

1
GHSA
GHSA-f9pm-2gc4-v2g5: Apple Safari before 62022-05-17