CVE-2009-2199
Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing…
Does this matter?
Lower severity and a low EPSS score (2.59%). Track it; it rarely justifies an emergency change on its own.
Description
Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified homoglyphs.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
- EPSS
- 2.59% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- apple/safari · apple/iphone os
- Source
- cve@mitre.org
References
- http://lists.apple.com/archives/security-announce/2009/Aug/msg00002.htmlPatch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
- http://secunia.com/advisories/36677Vendor Advisory
- http://secunia.com/advisories/43068Vendor Advisory
- http://support.apple.com/kb/HT3733Patch, Vendor Advisory
- http://support.apple.com/kb/HT3860
- http://www.securityfocus.com/bid/36026Patch
- http://www.securitytracker.com/id?1022719
- http://www.vupen.com/english/advisories/2011/0212Vendor Advisory
- http://lists.apple.com/archives/security-announce/2009/Aug/msg00002.htmlPatch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
- http://secunia.com/advisories/36677Vendor Advisory
- http://secunia.com/advisories/43068Vendor Advisory
- http://support.apple.com/kb/HT3733Patch, Vendor Advisory
- http://support.apple.com/kb/HT3860
- http://www.securityfocus.com/bid/36026Patch
- http://www.securitytracker.com/id?1022719
- http://www.vupen.com/english/advisories/2011/0212Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.