4.3
CVSSv2

CVE-2009-0162

Published: 13/05/2009 Updated: 08/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Safari prior to 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 prior to 10.5.7 and Windows allows remote malicious users to inject arbitrary web script or HTML via a crafted feed: URL.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 1.0

apple safari 1.0.0b1

apple safari 1.2

apple safari 1.0.3

apple safari 1.2.4

apple safari 1.2.5

apple safari 2

apple safari 2.0.3

apple safari 3.0

apple safari 3.0.0

apple safari 3.1.1

apple safari 3.1.2

apple safari 1.0.1

apple safari 1.0.0b2

apple safari 1.2.2

apple safari 1.2.3

apple safari 2.0.1

apple safari 2.0.2

apple safari 2.0.4

apple safari 3

apple safari 3.1.0

apple safari 3.1

apple safari

apple safari 0.9

apple safari 1.0.2

apple safari 1.1.0

apple safari 1.1

apple safari 1.3.2

apple safari 1.2.1

apple safari 1.3.1

apple safari 2.0

apple safari 2.0.0

apple safari 3.0.3

apple safari 3.0.4

apple safari 3.2.1

apple safari 4.0

apple safari 0.8

apple safari 1.0.0

apple safari 1.2.0

apple safari 1.1.1

apple safari 1.3.0

apple safari 1.3

apple safari 3.0.1

apple safari 3.0.2

apple safari 3.2

apple safari 3.2.0

Exploits

source: wwwsecurityfocuscom/bid/34925/info Apple Safari is prone to multiple input-validation vulnerabilities An attacker can exploit these issues by enticing an unsuspecting victim to visit a malicious website Successfully exploiting these issues will allow the attacker to execute arbitrary JavaScript code in the local security zone ...