MEDIUM
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to determining a security context through an approach that is not the "HTML 5 standard method."
Published Jun 10, 2009
4.3
MEDIUMCVSS 2.0
EPSS 2.66%
Description
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to determining a security context through an approach that is not the "HTML 5 standard method."
Affected products
No data.
Configuration 1
OR
- ≤ 4.0_beta
- 0.8
- 0.9
- 1.0
- 1.0.3
- 1.1
- 1.2
- 1.3
- 1.3.1
- 1.3.2
- 2.0
- 2.0.2
- 2.0.4
- 3.0
- 3.0.2
- 3.0.3
- 3.0.4
- 3.1
- 3.1.1
- 3.1.2
- 3.2.1
- 3.2.3
Configuration 2
OR
- ≤ 3.2.3
- 3.0
- 3.0.1
- 3.0.2
- 3.0.3
- 3.0.4
- 3.1
- 3.1.1
- 3.1.2
- 3.2
- 3.2.1
- 3.2.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (14)
- http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html vendor-advisoryx_refsource_APPLE
- http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html vendor-advisoryx_refsource_APPLEPatchVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html vendor-advisoryx_refsource_SUSE
- http://osvdb.org/54986 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/35379 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/43068 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1022344 vdb-entryx_refsource_SECTRACKPatch
- http://support.apple.com/kb/HT3613 x_refsource_CONFIRMPatch
- http://support.apple.com/kb/HT3639 x_refsource_CONFIRM
- http://www.securityfocus.com/bid/35260 vdb-entryx_refsource_BIDExploit
- http://www.securityfocus.com/bid/35320 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2009/1522 vdb-entryx_refsource_VUPENPatchVendor Advisory
- http://www.vupen.com/english/advisories/2009/1621 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2011/0212 vdb-entryx_refsource_VUPEN
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 10, 2009
Updated Aug 7, 2024
Reserved May 20, 2009
Link CVE-2009-1688
CISA Vulnrichment
Updated n/a