Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h983-8jqg-vmp6

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

EPSS

Процентиль: 61%
0.00417
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 16 лет назад

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

nvd
больше 16 лет назад

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.

debian
больше 16 лет назад

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL ...

EPSS

Процентиль: 61%
0.00417
Низкий

Дефекты

CWE-200