7.1
CVSSv2

CVE-2009-2200

Published: 12/08/2009 Updated: 17/02/2011
CVSS v2 Base Score: 7.1 | Impact Score: 6.9 | Exploitability Score: 8.6
VMScore: 632
Vector: AV:N/AC:M/Au:N/C:C/I:N/A:N

Vulnerability Summary

WebKit in Apple Safari prior to 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote malicious users to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 1.0.0b1

apple safari 1.0.0b2

apple safari 1.0.3

apple safari 1.1

apple safari 1.2.3

apple safari 1.2.4

apple safari 1.2.5

apple safari 2.0

apple safari 2.0.0

apple safari 2.0.3

apple safari 2.0.3_417.9.3

apple safari 3.0.1

apple safari 3.0.4

apple safari 4beta

apple safari 3.2

apple safari 3.1.2

apple safari 1.0

apple safari 1.0.0

apple safari 1.2.1

apple safari 1.2.2

apple safari 1.3.2

apple safari 3.0

apple safari 3.0.0

apple safari 3.0.0b

apple safari 3.0.3

apple safari 3.0.3b

apple safari 3.2.1

apple safari 3.2.0

apple safari 3.0.4_beta

apple safari

apple safari 4.0

apple safari 4.0.1

apple safari 1.0.1

apple safari 1.0.2

apple safari 1.1.0

apple safari 1.1.1

apple safari 1.3

apple safari 1.3.0

apple safari 2.0.1

apple safari 2.0.2

apple safari 2.0.4

apple safari 2.0.4_419.3

apple safari 3.0.1b

apple safari 3.0.2

apple safari beta2

apple safari 4.0_beta

apple safari 3.1.1

apple safari 3.1.0b

apple safari 0.8

apple safari 0.9

apple safari 1.2

apple safari 1.2.0

apple safari 1.3.1

apple safari 2.0_pre

apple safari 3

apple safari 3.0.2b

apple safari 3.2.2

apple safari 3.1.0

apple safari 3.1

apple safari 3.0.4b