CVE-2009-2066: Medium severity Safari vulnerability
Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2066?
CVE-2009-2066 is classified as a moderate severity vulnerability.
How do I fix CVE-2009-2066?
To mitigate CVE-2009-2066, users should upgrade to a patched version of Apple Safari.
What is CVE-2009-2066?
CVE-2009-2066 is a vulnerability in Apple Safari that allows potential man-in-the-middle attacks due to improper handling of mixed content.
Which versions of Apple Safari are affected by CVE-2009-2066?
CVE-2009-2066 affects multiple versions of Apple Safari including versions 1.0 through 3.2.
What types of attacks can exploit CVE-2009-2066?
CVE-2009-2066 can be exploited to execute arbitrary web scripts in the context of an HTTPS site via mixed content.