CVE-2009-1713
The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors.
- Affected products
- Debian, Safari, Libqt4-Assistant, Libqt4-Core, Libqt4-Dbg, Libqt4-Dbus, Libqt4-Designer, Libqt4-Dev
- Apple Safari
- ≤ 4.0_beta, 0.8, 0.9, 1.0, 1.0.3, 1.1, 1.2, 1.3, 1.3.1, 1.3.2, 2.0, 2.0.2, 2.0.4, 3.0, 3.0.2, 3.0.3, 3.0.4, 3.1, 3.1.1, 3.1.2, 3.2.1, 3.2.3
- CVSS 2.0
- 7.1 HIGH
- EPSS
- 2.1% (79th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2009-06-10
CVE-2009-1713 at NVD
1 known exploit for CVE-2009-1713
Proof-of-concept code and exploit modules indexed by Sploitus