Sploitus

CVE-2009-2841

2 known exploits for CVE-2009-2841

The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality, aka rdar problem 7271202.

Affected products
Safari, Webcore, Webkit
Apple Safari
≤ 4.0.3, 0.8, 0.9, 1.0, 1.0.0, 1.0.0b1, 1.0.0b2, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.2, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.4, 1.2.5, 1.3, 1.3.0, 1.3.1, 1.3.2, 2, 2.0, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.3_417.9.3, 2.0.4, 2.0.4_419.3, 2.0_pre, 3, 3.0, 3.0.0, 3.0.0b, 3.0.1, 3.0.1b, 3.0.2
CVSS 2.0
5.0 MEDIUM
EPSS
2.9% (86th percentile)
NVD status
Modified
Published
2009-11-13
CVE-2009-2841 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2009-2841

Proof-of-concept code and exploit modules indexed by Sploitus