PT-2009-2830 · Microsoft+1 · Windows Vista+3

Billy Rios

+2

·

Published

2009-02-12

·

Updated

2009-08-19

·

CVE-2009-0137

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Safari versions in Apple Mac OS X 10.4.11 and 10.5.6 Safari versions in Windows XP and Vista
Description The issue is related to input validation problems, allowing remote attackers to execute arbitrary JavaScript in the local security zone via a crafted feed URL.
Recommendations For Safari versions in Apple Mac OS X 10.4.11 and 10.5.6: update to a version with improved input validation. For Safari versions in Windows XP and Vista: update to a version with improved input validation. As a temporary workaround, consider restricting the use of feed URLs to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0137

Affected Products

Macos X
Safari
Windows Vista
Windows Xp