VulnerabilityModified
CVE-2008-1999
Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.
MEDIUM 5.0EPSS 1.41%
Does this matter?
Lower severity and a low EPSS score (1.41%). Track it; it rarely justifies an emergency change on its own.
Description
Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.41% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- apple/safari
- Source
- cve@mitre.org
References
- http://es.geocities.com/jplopezy/pruebasafari3.html
- http://secunia.com/advisories/29900Vendor Advisory
- http://securityreason.com/securityalert/3833
- http://www.securityfocus.com/archive/1/491192/100/0/threaded
- http://www.vupen.com/english/advisories/2008/1347
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41981
- http://es.geocities.com/jplopezy/pruebasafari3.html
- http://secunia.com/advisories/29900Vendor Advisory
- http://securityreason.com/securityalert/3833
- http://www.securityfocus.com/archive/1/491192/100/0/threaded
- http://www.vupen.com/english/advisories/2008/1347
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41981
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.