WebKit in Apple Safari prior to 5.0 on Mac OS X 10.5 up to and including 10.6, and prior to 4.1 on Mac OS X 10.4, does not properly handle clipboard (1) drag and (2) paste operations for URLs, which allows user-assisted remote malicious users to read arbitrary files via a crafted HTML document.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apple webkit |
||
apple safari |
||
apple safari 4.0.3 |
||
apple safari 4.0.2 |
||
apple safari 4.0 |
||
apple safari 4.0.4 |
||
apple safari 4.0.1 |
||
apple safari 4.0.0b |