10
CVE-2009-0137
- EPSS 0.51%
- Published 13.02.2009 00:30:05
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Multiple unspecified vulnerabilities in Safari RSS in Apple Mac OS X 10.4.11 and 10.5.6, and Windows XP and Vista, allow remote attackers to execute arbitrary JavaScript in the local security zone via a crafted feed: URL, related to "input validation issues."
Data is provided by the National Vulnerability Database (NVD)
Apple ≫ Safari
Apple ≫ macOS X Version10.4.11
Apple ≫ macOS X Version10.5.6
Apple ≫ macOS X Server Version10.4.11
Apple ≫ macOS X Server Version10.5.6
Microsoft ≫ Windows Vista
Microsoft ≫ Windows Xp
Apple ≫ macOS X Version10.5.6
Apple ≫ macOS X Server Version10.4.11
Apple ≫ macOS X Server Version10.5.6
Microsoft ≫ Windows Vista
Microsoft ≫ Windows Xp
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.51% | 0.658 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.