Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-2200

Опубликовано: 12 авг. 2009
Источник: debian
EPSS Низкий

Описание

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
kdelibsnot-affectedpackage
webkitnot-affectedpackage
qt4-x11not-affectedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=517273

  • http://trac.webkit.org/changeset/44905

  • http://trac.webkit.org/changeset/44909

EPSS

Процентиль: 61%
0.00417
Низкий

Связанные уязвимости

ubuntu
больше 16 лет назад

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

nvd
больше 16 лет назад

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

github
почти 4 года назад

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

EPSS

Процентиль: 61%
0.00417
Низкий