CVE-2009-1689

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving submission of a form to the about:blank URL, leading to security-context replacement.
References
Link Resource
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html Patch Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
http://osvdb.org/54988
http://secunia.com/advisories/35379 Vendor Advisory
http://secunia.com/advisories/43068
http://securitytracker.com/id?1022344
http://support.apple.com/kb/HT3613 Patch Vendor Advisory
http://support.apple.com/kb/HT3639
http://www.securityfocus.com/bid/35260 Exploit Patch
http://www.securityfocus.com/bid/35332
http://www.vupen.com/english/advisories/2009/1522 Patch Vendor Advisory
http://www.vupen.com/english/advisories/2009/1621
http://www.vupen.com/english/advisories/2011/0212
http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html Patch Vendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
http://osvdb.org/54988
http://secunia.com/advisories/35379 Vendor Advisory
http://secunia.com/advisories/43068
http://securitytracker.com/id?1022344
http://support.apple.com/kb/HT3613 Patch Vendor Advisory
http://support.apple.com/kb/HT3639
http://www.securityfocus.com/bid/35260 Exploit Patch
http://www.securityfocus.com/bid/35332
http://www.vupen.com/english/advisories/2009/1522 Patch Vendor Advisory
http://www.vupen.com/english/advisories/2009/1621
http://www.vupen.com/english/advisories/2011/0212
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:0.8:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:0.9:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:1.0:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:1.0.3:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:1.1:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:1.2:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:1.3:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:1.3.1:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:1.3.2:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0.2:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:2.0.4:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.2:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.3:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.4:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:3.1:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:3.1.1:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:3.1.2:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:3.2.1:-:mac:*:*:*:*:*
cpe:2.3:a:apple:safari:3.2.3:-:mac:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:apple:safari:*:-:windows:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0:-:windows:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.1:-:windows:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.2:-:windows:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.3:-:windows:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.4:-:windows:*:*:*:*:*
cpe:2.3:a:apple:safari:3.1:-:windows:*:*:*:*:*
cpe:2.3:a:apple:safari:3.1.1:-:windows:*:*:*:*:*
cpe:2.3:a:apple:safari:3.1.2:-:windows:*:*:*:*:*
cpe:2.3:a:apple:safari:3.2:-:windows:*:*:*:*:*
cpe:2.3:a:apple:safari:3.2.1:-:windows:*:*:*:*:*
cpe:2.3:a:apple:safari:3.2.2:-:windows:*:*:*:*:*

History

21 Nov 2024, 01:03

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html - () http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html -
References () http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html - Patch, Vendor Advisory () http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html - Patch, Vendor Advisory
References () http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html - () http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html -
References () http://osvdb.org/54988 - () http://osvdb.org/54988 -
References () http://secunia.com/advisories/35379 - Vendor Advisory () http://secunia.com/advisories/35379 - Vendor Advisory
References () http://secunia.com/advisories/43068 - () http://secunia.com/advisories/43068 -
References () http://securitytracker.com/id?1022344 - () http://securitytracker.com/id?1022344 -
References () http://support.apple.com/kb/HT3613 - Patch, Vendor Advisory () http://support.apple.com/kb/HT3613 - Patch, Vendor Advisory
References () http://support.apple.com/kb/HT3639 - () http://support.apple.com/kb/HT3639 -
References () http://www.securityfocus.com/bid/35260 - Exploit, Patch () http://www.securityfocus.com/bid/35260 - Exploit, Patch
References () http://www.securityfocus.com/bid/35332 - () http://www.securityfocus.com/bid/35332 -
References () http://www.vupen.com/english/advisories/2009/1522 - Patch, Vendor Advisory () http://www.vupen.com/english/advisories/2009/1522 - Patch, Vendor Advisory
References () http://www.vupen.com/english/advisories/2009/1621 - () http://www.vupen.com/english/advisories/2009/1621 -
References () http://www.vupen.com/english/advisories/2011/0212 - () http://www.vupen.com/english/advisories/2011/0212 -

Information

Published : 2009-06-10 14:30

Updated : 2024-11-21 01:03


NVD link : CVE-2009-1689

Mitre link : CVE-2009-1689

CVE.ORG link : CVE-2009-1689


JSON object : View

Products Affected

apple

  • safari
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')