6.8
CVSSv2

CVE-2011-3229

Published: 14/10/2011 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in Apple Safari prior to 5.1.1 allows remote malicious users to execute arbitrary JavaScript code, in a Safari Extensions context, via a crafted safari-extension: URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari

apple safari 5.0

apple safari 4.1.2

apple safari 4.0.1

apple safari 4.0.0b

apple safari 3.2.0

apple safari 3.1.2b

apple safari 3.1.0

apple safari 3.0.4b

apple safari 3.0.2b

apple safari 3.0.1

apple safari 3.0.0b

apple safari 2.0.4

apple safari 2.0.3

apple safari 2.0

apple safari 2

apple safari 1.2.5

apple safari 1.2.4

apple safari 1.1.0

apple safari 1.1

apple safari 1.0.1

apple safari 1.0.0b2

apple safari 5.0.4

apple safari 5.0.3

apple safari 4.0

apple safari 4.0.5

apple safari 3.2.2

apple safari 3.2.1b

apple safari 3.1.1

apple safari 3.1.0b

apple safari 3.0.4

apple safari 3.0.3b

apple safari 3.0.1b

apple safari 3.0.0

apple safari 3.0

apple safari 2.0.2

apple safari 1.3.2

apple safari 1.3.1

apple safari 5.0.2

apple safari 5.0.1

apple safari 4.0.4

apple safari 4.0.3

apple safari 4.0.2

apple safari 3.2.1

apple safari 3.2.0b

apple safari 3.0.3

apple safari 3

apple safari 2.0.1

apple safari 2.0.0

apple safari 1.3.0

apple safari 1.3

apple safari 1.2

apple safari 1.1.1

apple safari 1.0.3

apple safari 1.0.2

apple safari 1.2.1

apple safari 1.2.0

apple safari 1.0

apple safari 5.0.6

apple safari 5.0.5

apple safari 4.1.1

apple safari 4.1

apple safari 3.2.2b

apple safari 3.1.2

apple safari 3.1.1b

apple safari 3.0.2

apple safari 1.2.3

apple safari 1.2.2

apple safari 1.0b1

apple safari 1.0.0b1

apple safari 1.0.0

Exploits

Apple Safari versions 50 and later on Mac OS and Windows are vulnerable to a directory traversal issue with the handling of "safari-extension://" URLs Attackers can create malicious websites that trigger Safari to send files from the victim's system to the attacker Arbitrary Javascript can be executed in the web context of the Safari extension ...