6.8
CVSSv2

CVE-2009-2816

Published: 13/11/2009 Updated: 08/11/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari prior to 4.0.4 and Google Chrome prior to 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote malicious users to conduct cross-site request forgery (CSRF) attacks via a crafted web page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari

google chrome

apple iphone os

opensuse opensuse 11.2

opensuse opensuse 11.3

fedoraproject fedora 11

fedoraproject fedora 12

Vendor Advisories

Debian Bug report logs - #559759 webkit: multiple security issues Package: webkit; Maintainer for webkit is (unknown); Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Sun, 6 Dec 2009 22:36:01 UTC Severity: serious Tags: security Found in version 101-4 Done: Michael Gilbert <michaelsgilbert@gmail ...