CVE-2009-0123
Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for RSS feeds. NOTE: as of 20090114, the only disclosure is a vague pre-advisory. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.
- CVSS 2.0
- 7.1 HIGHAV:N/AC:M/Au:N/C:C/I:N/A:N
- EPSS
- 1.67% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/safari
- Source
- cve@mitre.org
References
- http://brian.mastenbrook.net/display/27
- http://isc.sans.org/diary.html?storyid=5689
- http://secunia.com/advisories/33458
- http://www.securityfocus.com/bid/33234
- http://www.securitytracker.com/id?1021581
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47917
- http://brian.mastenbrook.net/display/27
- http://isc.sans.org/diary.html?storyid=5689
- http://secunia.com/advisories/33458
- http://www.securityfocus.com/bid/33234
- http://www.securitytracker.com/id?1021581
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47917
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.