CVE-2009-1704
CFNetwork in Apple Safari before 4.0 misinterprets downloaded image files as local HTML documents in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript code by placing it in an image file.
- Apple Safari
- ≤ 4.0_beta, 0.8, 0.9, 1.0, 1.0.3, 1.1, 1.2, 1.3, 1.3.1, 1.3.2, 2.0, 2.0.2, 2.0.4, 3.0, 3.0.2, 3.0.3, 3.0.4, 3.1, 3.1.1, 3.1.2, 3.2.1, 3.2.3
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 2.5% (83th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2009-06-10
CVE-2009-1704 at NVD
1 known exploit for CVE-2009-1704
Proof-of-concept code and exploit modules indexed by Sploitus