CVE-2009-1715: XSS
Published Jun 10, 2009
·Updated
Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to script execution with incorrect privileges.
Affected Software
34 affected components
Safari=1.1
Safari=1.3.1
Safari=3.2.3
Safari=2.0.2
Safari=3.1
Safari=3.1.2
Safari=3.0
Safari=0.8
Safari=2.0
Safari=3.0.4
Safari=0.9
Safari=3.0.3
Safari=1.3.2
Safari=1.2
Safari<=4.0_beta
Safari=3.2.1
Safari=3.0.2
Safari=2.0.4
Safari=3.1.1
Safari=1.0.3
Safari=1.0
Safari=1.3
Safari=3.0.1
Safari=3.2
Safari=3.1.2
Safari<=3.2.3
Safari=3.0.3
Safari=3.0.2
Safari=3.1.1
Safari=3.0
Safari=3.1
Safari=3.2.2
Safari=3.2.1
Safari=3.0.4
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jun 10, 2009
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1715?
CVE-2009-1715 is considered a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2009-1715?
To fix CVE-2009-1715, update your Apple Safari browser to version 4.0 or later.
3
What types of attacks does CVE-2009-1715 allow?
CVE-2009-1715 allows user-assisted remote attackers to inject arbitrary web scripts or HTML.
4
Which versions of Safari are affected by CVE-2009-1715?
CVE-2009-1715 affects multiple versions of Apple Safari prior to 4.0, including versions from 0.8 to 3.2.3.
5
What can be compromised due to CVE-2009-1715?
Due to CVE-2009-1715, attackers may gain unauthorized access to read local files on the user's system.