Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h983-8jqg-vmp6

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

EPSS

Процентиль: 83%
0.02387
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
около 17 лет назад

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

nvd
около 17 лет назад

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

debian
около 17 лет назад

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL ...

EPSS

Процентиль: 83%
0.02387
Низкий

Дефекты

CWE-200