4.3
CVSSv2

CVE-2009-1684

Published: 10/06/2009 Updated: 17/02/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari prior to 4.0, iPhone OS 1.0 up to and including 2.2.1, and iPhone OS for iPod touch 1.1 up to and including 2.2.1 allows remote malicious users to inject arbitrary web script or HTML via an event handler that triggers script execution in the context of the next loaded document.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 3.1.1

apple safari 3.1

apple safari 1.3.1

apple safari 1.3.2

apple safari 3.0.2

apple safari 0.9

apple safari 1.0

apple safari 1.1

apple safari 2.0.4

apple safari 3.2.1

apple safari 3.0.4

apple safari 1.0.3

apple safari 1.2

apple safari 1.3

apple safari 3.2.3

apple safari

apple safari 3.1.2

apple safari 0.8

apple safari 2.0

apple safari 2.0.2

apple safari 3.0.3

apple safari 3.0

apple safari 3.0.1

apple safari 3.2.2

apple safari 3.2

Vendor Advisories

Several vulnerabilities have been discovered in WebKit, a Web content engine library for Gtk+ The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-0945 Array index error in the insertItemBefore method in WebKit, allows remote attackers to execute arbitrary code via a document with a SVGPathList data structu ...
Debian Bug report logs - #534946 webkit: CVE-2009-1698 CVE-2009-1690 CVE-2009-1687 Package: webkit; Maintainer for webkit is (unknown); Reported by: Giuseppe Iuculano <giuseppe@iuculanoit> Date: Sun, 28 Jun 2009 12:48:02 UTC Severity: grave Tags: lenny, patch, security Found in version 101-4 Fixed in versions 115-1, ...
Debian Bug report logs - #535793 webkit: deluge of security vulnerabilities Package: webkit; Maintainer for webkit is (unknown); Reported by: Michael S Gilbert <michaelsgilbert@gmailcom> Date: Sun, 5 Jul 2009 05:18:04 UTC Severity: grave Tags: fixed-upstream, security Found in version 101-4 Fixed in version 1121-1 ...

Exploits

source: wwwsecurityfocuscom/bid/35315/info WebKit is prone to a cross-domain scripting vulnerability because it fails to properly restrict the access of JavaScript code when loading new webpages A remote attacker can exploit this vulnerability to bypass the same-origin policy and obtain potentially sensitive information or to launch spo ...