Security Advisory

CVE-2009-2200

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2009-08-12 19:00:00
Last updated 2024-08-07 05:44:55
Assigner mitre
State PUBLISHED

Description

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.