5
CVSSv2

CVE-2009-2841

Published: 13/11/2009 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari prior to 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote malicious users to trigger sub-resource requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality, aka rdar problem 7271202.

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari 1.0

apple safari 1.0.3

apple safari 0.9

apple safari 0.8

apple safari 1.3

apple safari 1.2.5

apple safari 3.0.0b

apple safari 3.0.0

apple safari 1.0.0b2

apple safari 1.0.0b1

apple safari 2

apple safari 1.3.2

apple safari 1.2.2

apple safari 1.2.1

apple safari 2.0_pre

apple safari 2.0.4_419.3

apple safari 2.0.3

apple safari 2.0.2

apple safari 3.0.2b

apple safari 3.0.2

apple safari 3.0.1b

apple safari 3.2

apple safari 1.1.1

apple safari 1.1.0

apple safari 1.0.0

apple safari 1.3.1

apple safari 1.3.0

apple safari 1.2.0

apple safari 1.2

apple safari 3.0.1

apple safari 2.0.4

apple safari 2.0.3_417.9.3

apple safari 2.0.1

apple safari 3.0.4b

apple safari 3.1

apple safari 3.2.1

apple safari 3.2.2

apple safari

apple safari 3.2.0

apple safari 4.0.2

apple safari 4.0

apple safari 3.0.4_beta

apple safari 3.0.4

apple safari 3.1.0

apple safari 3.1.0b

apple safari 3.2.3

apple safari 1.0.2

apple safari 1.0.1

apple safari 2.0.0

apple safari 2.0

apple safari 1.2.4

apple safari 1.2.3

apple safari 3.0

apple safari 3

apple safari 3.0.3b

apple safari 3.0.3

apple safari 3.1.1

apple safari 3.1.2

apple safari 4.0.0b

apple safari 4.0.1

Vendor Advisories

Debian Bug report logs - #559759 webkit: multiple security issues Package: webkit; Maintainer for webkit is (unknown); Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Sun, 6 Dec 2009 22:36:01 UTC Severity: serious Tags: security Found in version 101-4 Done: Michael Gilbert <michaelsgilbert@gmail ...