CVE-2009-1696
WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 uses predictable random numbers in JavaScript applications, which makes it easier for remote web servers to track the behavior of a Safari user during a session.
- Affected products
- Safari, Ios, Iphone Os For Ipod Touch
- Apple Safari
- ≤ 4.0_beta, 0.8, 0.9, 1.0, 1.0.3, 1.1, 1.2, 1.3, 1.3.1, 1.3.2, 2.0, 2.0.2, 2.0.4, 3.0, 3.0.2, 3.0.3, 3.0.4, 3.1, 3.1.1, 3.1.2, 3.2.1, 3.2.3
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 2.3% (82th percentile)
- Weakness
- CWE-310
- NVD status
- Modified
- Published
- 2009-06-10
CVE-2009-1696 at NVD
2 known exploits for CVE-2009-1696
Proof-of-concept code and exploit modules indexed by Sploitus