First published: Wed Jun 10 2009(Updated: )
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to insufficient access control for standard JavaScript prototypes in other domains.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | =3.1.2 | |
Apple Mobile Safari | =3.2.1 | |
Apple Mobile Safari | =0.9 | |
Apple Mobile Safari | =1.3.2 | |
Apple Mobile Safari | =1.2 | |
Apple Mobile Safari | =3.0.4 | |
Apple Mobile Safari | =3.0.3 | |
Apple Mobile Safari | =1.3.1 | |
Apple Mobile Safari | =2.0.4 | |
Apple Mobile Safari | =3.0 | |
Apple Mobile Safari | =3.2.3 | |
Apple Mobile Safari | =1.1 | |
Apple Mobile Safari | <=4.0_beta | |
Apple Mobile Safari | =3.1 | |
Apple Mobile Safari | =2.0 | |
Apple Mobile Safari | =3.0.2 | |
Apple Mobile Safari | =1.0.3 | |
Apple Mobile Safari | =1.0 | |
Apple Mobile Safari | =2.0.2 | |
Apple Mobile Safari | =3.1.1 | |
Apple Mobile Safari | =1.3 | |
Apple Mobile Safari | =0.8 | |
Apple Mobile Safari | =3.2 | |
Apple Mobile Safari | =3.0.3 | |
Apple Mobile Safari | =3.0.1 | |
Apple Mobile Safari | =3.1.2 | |
Apple Mobile Safari | <=3.2.3 | |
Apple Mobile Safari | =3.0.2 | |
Apple Mobile Safari | =3.1 | |
Apple Mobile Safari | =3.1.1 | |
Apple Mobile Safari | =3.0 | |
Apple Mobile Safari | =3.2.2 | |
Apple Mobile Safari | =3.2.1 | |
Apple Mobile Safari | =3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1691 is classified as a high severity cross-site scripting vulnerability.
To fix CVE-2009-1691, users should upgrade to the latest version of Apple Safari that addresses this vulnerability.
Affected versions of Safari include all versions prior to 4.0 on both Mac and Windows.
CVE-2009-1691 is a cross-site scripting (XSS) vulnerability.
Yes, CVE-2009-1691 can be exploited by remote attackers to inject arbitrary web script or HTML.