6.8
CVSSv2

CVE-2011-3230

Published: 14/10/2011 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apple Safari prior to 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote malicious users to execute arbitrary code via a crafted web site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple safari

apple safari 5.0.6

apple safari 4.1.2

apple safari 4.1.1

apple safari 4.1

apple safari 4.0.0b

apple safari 4.0

apple safari 3.1.2b

apple safari 3.1.2

apple safari 3.0.4b

apple safari 3.0.4

apple safari 3.0.2b

apple safari 3.0.2

apple safari 3.0.0b

apple safari 2.0.3

apple safari 2

apple safari 1.3.2

apple safari 1.2.4

apple safari 1.2.3

apple safari 1.0b1

apple safari 1.0

apple safari 1.0.0b2

apple safari 1.0.0b1

apple safari 5.0.1

apple safari 5.0

apple safari 4.0.2

apple safari 4.0.1

apple safari 3.2.0b

apple safari 3.2.0

apple safari 3.1.0

apple safari 3.0.3

apple safari 3.0.1

apple safari 2.0.4

apple safari 2.0.0

apple safari 2.0

apple safari 1.3

apple safari 1.2.5

apple safari 1.1.0

apple safari 1.1

apple safari 1.0.2

apple safari 1.0.1

apple safari 5.0.3

apple safari 5.0.2

apple safari 4.0.4

apple safari 4.0.3

apple safari 3.2.1b

apple safari 3.2.1

apple safari 3.1.0b

apple safari 3.0.3b

apple safari 3.0.1b

apple safari 3.0

apple safari 3

apple safari 2.0.2

apple safari 2.0.1

apple safari 1.3.1

apple safari 1.3.0

apple safari 1.2.0

apple safari 1.2

apple safari 1.1.1

apple safari 1.0.3

apple safari 5.0.5

apple safari 5.0.4

apple safari 4.0.5

apple safari 3.2.2b

apple safari 3.2.2

apple safari 3.1.1b

apple safari 3.1.1

apple safari 3.0.0

apple safari 1.2.2

apple safari 1.2.1

apple safari 1.0.0

Exploits

## # $Id: safari_file_policyrb 13967 2011-10-17 03:49:49Z todb $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' requ ...
Apple Safari versions prior to 511 fail to enforce an intended policy for file:// URLs and in turn allows for remote attackers to execute code ...