5.8

CVE-2009-2199

Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified homoglyphs.

Data is provided by the National Vulnerability Database (NVD)
AppleSafari Version <= 4.0.2
AppleSafari Version2.0
AppleSafari Version2.0.0
AppleSafari Version2.0.1
AppleSafari Version2.0.2
AppleSafari Version2.0.3
AppleSafari Version2.0.3 Update417.8
AppleSafari Version2.0.3 Update417.9
AppleSafari Version2.0.3 Update417.9.2
AppleSafari Version2.0.3 Update417.9.3
AppleSafari Version2.0.4
AppleSafari Version3.0
AppleSafari Version3.0.0
AppleSafari Version3.0.0b
AppleSafari Version3.0.1
AppleSafari Version3.0.1 Updatebeta
AppleSafari Version3.0.1b
AppleSafari Version3.0.2
AppleSafari Version3.0.2b
AppleSafari Version3.0.3
AppleSafari Version3.0.3b
AppleSafari Version3.0.4
AppleSafari Version3.0.4b
AppleSafari Version3.1.0
AppleSafari Version3.1.0b
AppleSafari Version3.1.1
AppleSafari Version3.1.2
AppleSafari Version3.2.0
AppleSafari Version3.2.1
AppleSafari Version3.2.2
AppleSafari Version4.0
AppleSafari Version4.0.0b
AppleSafari Version4.0.1
AppleiPhone OS Version <= 3.0.1
   AppleiPhone OS
AppleiPhone OS Version1.0.0
   AppleiPhone OS
AppleiPhone OS Version1.0.1
   AppleiPhone OS
AppleiPhone OS Version1.0.2
   AppleiPhone OS
AppleiPhone OS Version1.1.0
   AppleiPhone OS
AppleiPhone OS Version1.1.1
   AppleiPhone OS
AppleiPhone OS Version1.1.2
   AppleiPhone OS
AppleiPhone OS Version1.1.3
   AppleiPhone OS
AppleiPhone OS Version1.1.4
   AppleiPhone OS
AppleiPhone OS Version1.1.5
   AppleiPhone OS
AppleiPhone OS Version2.0
   AppleiPhone OS
AppleiPhone OS Version2.0.0
   AppleiPhone OS
AppleiPhone OS Version2.0.1
   AppleiPhone OS
AppleiPhone OS Version2.0.2
   AppleiPhone OS
AppleiPhone OS Version2.1
   AppleiPhone OS
AppleiPhone OS Version2.1.1
   AppleiPhone OS
AppleiPhone OS Version2.2
   AppleiPhone OS
AppleiPhone OS Version2.2.1
   AppleiPhone OS
AppleiPhone OS Version3.0
   AppleiPhone OS
AppleiPhone OS Version <= 3.1
   AppleIpod Touch
AppleiPhone OS Version1.0.0
   AppleIpod Touch
AppleiPhone OS Version1.0.1
   AppleIpod Touch
AppleiPhone OS Version1.0.2
   AppleIpod Touch
AppleiPhone OS Version1.1.0
   AppleIpod Touch
AppleiPhone OS Version1.1.1
   AppleIpod Touch
AppleiPhone OS Version1.1.2
   AppleIpod Touch
AppleiPhone OS Version1.1.3
   AppleIpod Touch
AppleiPhone OS Version1.1.4
   AppleIpod Touch
AppleiPhone OS Version1.1.5
   AppleIpod Touch
AppleiPhone OS Version2.0
   AppleIpod Touch
AppleiPhone OS Version2.0.0
   AppleIpod Touch
AppleiPhone OS Version2.0.1
   AppleIpod Touch
AppleiPhone OS Version2.0.2
   AppleIpod Touch
AppleiPhone OS Version2.1
   AppleIpod Touch
AppleiPhone OS Version2.1.1
   AppleIpod Touch
AppleiPhone OS Version2.2
   AppleIpod Touch
AppleiPhone OS Version2.2.1
   AppleIpod Touch
AppleiPhone OS Version3.0
   AppleIpod Touch
AppleiPhone OS Version3.0.1
   AppleIpod Touch
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.42% 0.788
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:N/I:P/A:P