9.3

CVE-2009-1708

Exploit

Apple Safari before 4.0 does not prevent calls to the open-help-anchor URL handler by web sites, which allows remote attackers to open arbitrary local help files, and execute arbitrary code or obtain sensitive information, via a crafted call.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AppleSafari Update- Editionmac Version <= 4.0_beta
AppleSafari Version0.8 Update- Editionmac
AppleSafari Version0.9 Update- Editionmac
AppleSafari Version1.0 Update- Editionmac
AppleSafari Version1.0.3 Update- Editionmac
AppleSafari Version1.1 Update- Editionmac
AppleSafari Version1.2 Update- Editionmac
AppleSafari Version1.3 Update- Editionmac
AppleSafari Version1.3.1 Update- Editionmac
AppleSafari Version1.3.2 Update- Editionmac
AppleSafari Version2.0 Update- Editionmac
AppleSafari Version2.0.2 Update- Editionmac
AppleSafari Version2.0.4 Update- Editionmac
AppleSafari Version3.0 Update- Editionmac
AppleSafari Version3.0.2 Update- Editionmac
AppleSafari Version3.0.3 Update- Editionmac
AppleSafari Version3.0.4 Update- Editionmac
AppleSafari Version3.1 Update- Editionmac
AppleSafari Version3.1.1 Update- Editionmac
AppleSafari Version3.1.2 Update- Editionmac
AppleSafari Version3.2.1 Update- Editionmac
AppleSafari Version3.2.3 Update- Editionmac
AppleSafari Update- Editionwindows Version <= 3.2.3
AppleSafari Version3.0 Update- Editionwindows
AppleSafari Version3.0.1 Update- Editionwindows
AppleSafari Version3.0.2 Update- Editionwindows
AppleSafari Version3.0.3 Update- Editionwindows
AppleSafari Version3.0.4 Update- Editionwindows
AppleSafari Version3.1 Update- Editionwindows
AppleSafari Version3.1.1 Update- Editionwindows
AppleSafari Version3.1.2 Update- Editionwindows
AppleSafari Version3.2 Update- Editionwindows
AppleSafari Version3.2.1 Update- Editionwindows
AppleSafari Version3.2.2 Update- Editionwindows
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.27% 0.867
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C