First published: Wed Aug 12 2009(Updated: )
Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.4. | |
Apple iOS and macOS | =10.5.7 | |
Apple iOS and macOS | =10.5.8 | |
Apple macOS Server | =10.4.11 | |
Apple macOS Server | =10.5.7 | |
Apple macOS Server | =10.5.8 | |
Microsoft Windows Vista | ||
Microsoft Windows XP | ||
Apple Mobile Safari | =4.0 | |
Apple Mobile Safari | =4.0.1 | |
Apple Mobile Safari | =4.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2196 has been classified with medium severity due to its potential for phishing attacks.
To fix CVE-2009-2196, update Apple Safari to version 4.0.3 or later.
CVE-2009-2196 affects Apple Safari versions 4.0, 4.0.1, and 4.0.2.
CVE-2009-2196 affects various versions of macOS and Apple Mac OS X Server as well as some Microsoft Windows versions.
CVE-2009-2196 enables remote web servers to manipulate the Top Sites view in Safari, potentially leading to phishing attacks.