WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Safari | — | Upgrade to Apple Safari version 4.0.3Uninstall Apple Safari on Windows | Jan 5, 2012 | Aug 12, 2009 |
| Suse | — | Upgrade webkit-jscUpgrade libwebkit-1_0-2-32bitUpgrade libwebkit-1_0-2Upgrade libwebkit-langUpgrade libwebkit-devel | Feb 17, 2015 | Aug 12, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub