CVE-2009-1712
WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element.
- Apple Safari
- ≤ 4.0_beta, 0.8, 0.9, 1.0, 1.0.3, 1.1, 1.2, 1.3, 1.3.1, 1.3.2, 2.0, 2.0.2, 2.0.4, 3.0, 3.0.2, 3.0.3, 3.0.4, 3.1, 3.1.1, 3.1.2, 3.2.1, 3.2.3
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 7.7% (94th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2009-06-10
CVE-2009-1712 at NVD
1 known exploit for CVE-2009-1712
Proof-of-concept code and exploit modules indexed by Sploitus