Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-1699

The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.056
EPSS Ranking 89.9%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 7.1
References
Products affected by CVE-2009-1699
  • Apple » Safari » Version: N/A
    cpe:2.3:a:apple:safari:-
  • Apple » Safari » Version: 1.0
    cpe:2.3:a:apple:safari:1.0
  • Apple » Safari » Version: 1.0.0
    cpe:2.3:a:apple:safari:1.0.0
  • Apple » Safari » Version: 1.0.0b1
    cpe:2.3:a:apple:safari:1.0.0b1
  • Apple » Safari » Version: 1.0.0b2
    cpe:2.3:a:apple:safari:1.0.0b2
  • Apple » Safari » Version: 1.0.1
    cpe:2.3:a:apple:safari:1.0.1
  • Apple » Safari » Version: 1.0.2
    cpe:2.3:a:apple:safari:1.0.2
  • Apple » Safari » Version: 1.0.3
    cpe:2.3:a:apple:safari:1.0.3
  • Apple » Safari » Version: 1.0b1
    cpe:2.3:a:apple:safari:1.0b1
  • Apple » Safari » Version: 1.1
    cpe:2.3:a:apple:safari:1.1
  • Apple » Safari » Version: 1.1.0
    cpe:2.3:a:apple:safari:1.1.0
  • Apple » Safari » Version: 1.1.1
    cpe:2.3:a:apple:safari:1.1.1
  • Apple » Safari » Version: 1.2
    cpe:2.3:a:apple:safari:1.2
  • Apple » Safari » Version: 1.2.0
    cpe:2.3:a:apple:safari:1.2.0
  • Apple » Safari » Version: 1.2.1
    cpe:2.3:a:apple:safari:1.2.1
  • Apple » Safari » Version: 1.2.2
    cpe:2.3:a:apple:safari:1.2.2
  • Apple » Safari » Version: 1.2.3
    cpe:2.3:a:apple:safari:1.2.3
  • Apple » Safari » Version: 1.2.4
    cpe:2.3:a:apple:safari:1.2.4
  • Apple » Safari » Version: 1.2.5
    cpe:2.3:a:apple:safari:1.2.5
  • Apple » Safari » Version: 1.3
    cpe:2.3:a:apple:safari:1.3
  • Apple » Safari » Version: 1.3.0
    cpe:2.3:a:apple:safari:1.3.0
  • Apple » Safari » Version: 1.3.1
    cpe:2.3:a:apple:safari:1.3.1
  • Apple » Safari » Version: 1.3.2
    cpe:2.3:a:apple:safari:1.3.2
  • Apple » Safari » Version: 2
    cpe:2.3:a:apple:safari:2
  • Apple » Safari » Version: 2.0
    cpe:2.3:a:apple:safari:2.0
  • Apple » Safari » Version: 2.0.0
    cpe:2.3:a:apple:safari:2.0.0
  • Apple » Safari » Version: 2.0.1
    cpe:2.3:a:apple:safari:2.0.1
  • Apple » Safari » Version: 2.0.2
    cpe:2.3:a:apple:safari:2.0.2
  • Apple » Safari » Version: 2.0.3
    cpe:2.3:a:apple:safari:2.0.3
  • Apple » Safari » Version: 2.0.4
    cpe:2.3:a:apple:safari:2.0.4
  • Apple » Safari » Version: 3
    cpe:2.3:a:apple:safari:3
  • Apple » Safari » Version: 3.0
    cpe:2.3:a:apple:safari:3.0
  • Apple » Safari » Version: 3.0.0
    cpe:2.3:a:apple:safari:3.0.0
  • Apple » Safari » Version: 3.0.0b
    cpe:2.3:a:apple:safari:3.0.0b
  • Apple » Safari » Version: 3.0.1
    cpe:2.3:a:apple:safari:3.0.1
  • Apple » Safari » Version: 3.0.1b
    cpe:2.3:a:apple:safari:3.0.1b
  • Apple » Safari » Version: 3.0.2
    cpe:2.3:a:apple:safari:3.0.2
  • Apple » Safari » Version: 3.0.2b
    cpe:2.3:a:apple:safari:3.0.2b
  • Apple » Safari » Version: 3.0.3
    cpe:2.3:a:apple:safari:3.0.3
  • Apple » Safari » Version: 3.0.3b
    cpe:2.3:a:apple:safari:3.0.3b
  • Apple » Safari » Version: 3.0.4
    cpe:2.3:a:apple:safari:3.0.4
  • Apple » Safari » Version: 3.0.4b
    cpe:2.3:a:apple:safari:3.0.4b
  • Apple » Safari » Version: 3.0.5
    cpe:2.3:a:apple:safari:3.0.5
  • Apple » Safari » Version: 3.1.0
    cpe:2.3:a:apple:safari:3.1.0
  • Apple » Safari » Version: 3.1.0b
    cpe:2.3:a:apple:safari:3.1.0b
  • Apple » Safari » Version: 3.1.1
    cpe:2.3:a:apple:safari:3.1.1
  • Apple » Safari » Version: 3.1.1b
    cpe:2.3:a:apple:safari:3.1.1b
  • Apple » Safari » Version: 3.1.2
    cpe:2.3:a:apple:safari:3.1.2
  • Apple » Safari » Version: 3.1.2b
    cpe:2.3:a:apple:safari:3.1.2b
  • Apple » Safari » Version: 3.2.0
    cpe:2.3:a:apple:safari:3.2.0
  • Apple » Safari » Version: 3.2.0b
    cpe:2.3:a:apple:safari:3.2.0b
  • Apple » Safari » Version: 3.2.1
    cpe:2.3:a:apple:safari:3.2.1
  • Apple » Safari » Version: 3.2.1b
    cpe:2.3:a:apple:safari:3.2.1b
  • Apple » Safari » Version: 3.2.2
    cpe:2.3:a:apple:safari:3.2.2
  • Apple » Safari » Version: 3.2.2b
    cpe:2.3:a:apple:safari:3.2.2b
  • Apple » Iphone Os » Version: 1.0.0
    cpe:2.3:o:apple:iphone_os:1.0.0
  • Apple » Iphone Os » Version: 1.0.1
    cpe:2.3:o:apple:iphone_os:1.0.1
  • Apple » Iphone Os » Version: 1.0.2
    cpe:2.3:o:apple:iphone_os:1.0.2
  • Apple » Iphone Os » Version: 1.1.0
    cpe:2.3:o:apple:iphone_os:1.1.0
  • Apple » Iphone Os » Version: 1.1.1
    cpe:2.3:o:apple:iphone_os:1.1.1
  • Apple » Iphone Os » Version: 1.1.2
    cpe:2.3:o:apple:iphone_os:1.1.2
  • Apple » Iphone Os » Version: 1.1.3
    cpe:2.3:o:apple:iphone_os:1.1.3
  • Apple » Iphone Os » Version: 1.1.4
    cpe:2.3:o:apple:iphone_os:1.1.4
  • Apple » Iphone Os » Version: 1.1.5
    cpe:2.3:o:apple:iphone_os:1.1.5
  • Apple » Iphone Os » Version: 2.0
    cpe:2.3:o:apple:iphone_os:2.0
  • Apple » Iphone Os » Version: 2.0.0
    cpe:2.3:o:apple:iphone_os:2.0.0
  • Apple » Iphone Os » Version: 2.0.1
    cpe:2.3:o:apple:iphone_os:2.0.1
  • Apple » Iphone Os » Version: 2.0.2
    cpe:2.3:o:apple:iphone_os:2.0.2
  • Apple » Iphone Os » Version: 2.1
    cpe:2.3:o:apple:iphone_os:2.1
  • Apple » Iphone Os » Version: 2.1.1
    cpe:2.3:o:apple:iphone_os:2.1.1
  • Apple » Iphone Os » Version: 2.2
    cpe:2.3:o:apple:iphone_os:2.2
  • Apple » Iphone Os » Version: 2.2.1
    cpe:2.3:o:apple:iphone_os:2.2.1
  • Canonical » Ubuntu Linux » Version: 8.10
    cpe:2.3:o:canonical:ubuntu_linux:8.10
  • Canonical » Ubuntu Linux » Version: 9.04
    cpe:2.3:o:canonical:ubuntu_linux:9.04
  • Opensuse » Opensuse » Version: 11.2
    cpe:2.3:o:opensuse:opensuse:11.2
  • Opensuse » Opensuse » Version: 11.3
    cpe:2.3:o:opensuse:opensuse:11.3


Contact Us

Shodan ® - All rights reserved