First published: Fri Feb 13 2009(Updated: )
Multiple unspecified vulnerabilities in Safari RSS in Apple Mac OS X 10.4.11 and 10.5.6, and Windows XP and Vista, allow remote attackers to execute arbitrary JavaScript in the local security zone via a crafted feed: URL, related to "input validation issues."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | ||
Apple iOS and macOS | =10.4.11 | |
Apple iOS and macOS | =10.5.6 | |
Apple macOS Server | =10.4.11 | |
Apple macOS Server | =10.5.6 | |
Microsoft Windows Vista | ||
Microsoft Windows XP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0137 is considered a high-severity vulnerability due to its potential for remote code execution.
To address CVE-2009-0137, update your version of Safari or apply the security patches provided by Apple.
CVE-2009-0137 affects Safari RSS on Apple Mac OS X 10.4.11, 10.5.6, and Windows XP and Vista.
CVE-2009-0137 can enable remote attackers to execute arbitrary JavaScript in the local security zone.
Yes, CVE-2009-0137 is resolved in later versions of Safari that include necessary security updates.