4.3

CVE-2011-3426

Cross-site scripting (XSS) vulnerability in Safari in Apple iOS before 5 allows remote web servers to inject arbitrary web script or HTML via a file accompanied by a "Content-Disposition: attachment" HTTP header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AppleiPhone OS Version3.0 Update- Editioniphone
AppleiPhone OS Version3.1
AppleiPhone OS Version3.1 Update- Editioniphone
AppleiPhone OS Version3.1 Update- Editionipodtouch
AppleiPhone OS Version3.1.2 Update- Editioniphone
AppleiPhone OS Version3.1.3 Update- Editioniphone
AppleiPhone OS Version3.2 Update- Editioniphone
AppleiPhone OS Version3.2 Update- Editionipodtouch
AppleiPhone OS Version3.2.1
AppleiPhone OS Version3.2.1 Update- Editionipad
AppleiPhone OS Version3.2.2
AppleiPhone OS Version4.0
AppleiPhone OS Version4.0 Update- Editioniphone
AppleiPhone OS Version4.0 Update- Editionipodtouch
AppleiPhone OS Version4.0.1
AppleiPhone OS Version4.0.1 Update- Editioniphone
AppleiPhone OS Version4.0.1 Update- Editionipodtouch
AppleiPhone OS Version4.0.2
AppleiPhone OS Version4.1
AppleiPhone OS Version4.2.1
AppleiPhone OS Version4.2.5
AppleiPhone OS Version4.2.8
AppleiPhone OS Version4.3.0
AppleiPhone OS Version4.3.1
AppleiPhone OS Version4.3.2
AppleiPhone OS Version4.3.3
AppleiPhone OS Version4.3.5
AppleiPhone OS Version4.3.5 Update- Editionipad
AppleiPhone OS Version4.3.5 Update- Editionipodtouch
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.88% 0.731
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.