CVE-2009-2841
Mandriva Linux Security Advisory 2011-039
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality, aka rdar problem 7271202.
WebKit en Apple Safari en versiones anteriores a la 4.0.4 en Mac OS X no realiza las devoluciones de llamada esperadas para elementos multimedia HTML 5 que tienen URLs externas para recursos multimedia, lo que permite a atacantes remotos disparar peticiones a sitios web de su elección mediante un documento HTML manipulado, tal como se ha demostrado por un mensaje de correo electrónico HTML que usa un elemento multimedia para la funcionalidad X-Confirm-Reading-To.
Multiple cross-site scripting, denial of service and arbitrary code execution security flaws were discovered in webkit. The updated packages have been upgraded to the latest version to correct these issues.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-08-17 CVE Reserved
- 2009-11-13 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (25)
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|---|---|
| http://lists.apple.com/archives/security-announce/2009/Nov/msg00001.html | 2017-08-17 | |
| http://support.apple.com/kb/HT3949 | 2017-08-17 |
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | <= 4.0.3 Search vendor "Apple" for product "Safari" and version " <= 4.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 0.8 Search vendor "Apple" for product "Safari" and version "0.8" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 0.9 Search vendor "Apple" for product "Safari" and version "0.9" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.0 Search vendor "Apple" for product "Safari" and version "1.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.0 Search vendor "Apple" for product "Safari" and version "1.0" | beta |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.0 Search vendor "Apple" for product "Safari" and version "1.0" | beta2 |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.0.0 Search vendor "Apple" for product "Safari" and version "1.0.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.0.0b1 Search vendor "Apple" for product "Safari" and version "1.0.0b1" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.0.0b2 Search vendor "Apple" for product "Safari" and version "1.0.0b2" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.0.1 Search vendor "Apple" for product "Safari" and version "1.0.1" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.0.2 Search vendor "Apple" for product "Safari" and version "1.0.2" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.0.3 Search vendor "Apple" for product "Safari" and version "1.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.1.0 Search vendor "Apple" for product "Safari" and version "1.1.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.1.1 Search vendor "Apple" for product "Safari" and version "1.1.1" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.2 Search vendor "Apple" for product "Safari" and version "1.2" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.2.0 Search vendor "Apple" for product "Safari" and version "1.2.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.2.1 Search vendor "Apple" for product "Safari" and version "1.2.1" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.2.2 Search vendor "Apple" for product "Safari" and version "1.2.2" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.2.3 Search vendor "Apple" for product "Safari" and version "1.2.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.2.4 Search vendor "Apple" for product "Safari" and version "1.2.4" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.2.5 Search vendor "Apple" for product "Safari" and version "1.2.5" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.3 Search vendor "Apple" for product "Safari" and version "1.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.3.0 Search vendor "Apple" for product "Safari" and version "1.3.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.3.1 Search vendor "Apple" for product "Safari" and version "1.3.1" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 1.3.2 Search vendor "Apple" for product "Safari" and version "1.3.2" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2 Search vendor "Apple" for product "Safari" and version "2" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0 Search vendor "Apple" for product "Safari" and version "2.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.0 Search vendor "Apple" for product "Safari" and version "2.0.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.1 Search vendor "Apple" for product "Safari" and version "2.0.1" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.2 Search vendor "Apple" for product "Safari" and version "2.0.2" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.3 Search vendor "Apple" for product "Safari" and version "2.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.3 Search vendor "Apple" for product "Safari" and version "2.0.3" | 417.8 |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.3 Search vendor "Apple" for product "Safari" and version "2.0.3" | 417.9 |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.3 Search vendor "Apple" for product "Safari" and version "2.0.3" | 417.9.2 |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.3 Search vendor "Apple" for product "Safari" and version "2.0.3" | 417.9.3 |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.3_417.9.3 Search vendor "Apple" for product "Safari" and version "2.0.3_417.9.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.4 Search vendor "Apple" for product "Safari" and version "2.0.4" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0.4_419.3 Search vendor "Apple" for product "Safari" and version "2.0.4_419.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 2.0_pre Search vendor "Apple" for product "Safari" and version "2.0_pre" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3 Search vendor "Apple" for product "Safari" and version "3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0 Search vendor "Apple" for product "Safari" and version "3.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.0 Search vendor "Apple" for product "Safari" and version "3.0.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.0b Search vendor "Apple" for product "Safari" and version "3.0.0b" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.1 Search vendor "Apple" for product "Safari" and version "3.0.1" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.1 Search vendor "Apple" for product "Safari" and version "3.0.1" | beta |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.1b Search vendor "Apple" for product "Safari" and version "3.0.1b" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.2 Search vendor "Apple" for product "Safari" and version "3.0.2" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.2b Search vendor "Apple" for product "Safari" and version "3.0.2b" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.3 Search vendor "Apple" for product "Safari" and version "3.0.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.3b Search vendor "Apple" for product "Safari" and version "3.0.3b" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.4 Search vendor "Apple" for product "Safari" and version "3.0.4" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.4_beta Search vendor "Apple" for product "Safari" and version "3.0.4_beta" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.0.4b Search vendor "Apple" for product "Safari" and version "3.0.4b" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.1 Search vendor "Apple" for product "Safari" and version "3.1" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.1.0 Search vendor "Apple" for product "Safari" and version "3.1.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.1.0b Search vendor "Apple" for product "Safari" and version "3.1.0b" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.1.1 Search vendor "Apple" for product "Safari" and version "3.1.1" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.1.2 Search vendor "Apple" for product "Safari" and version "3.1.2" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.2 Search vendor "Apple" for product "Safari" and version "3.2" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.2.0 Search vendor "Apple" for product "Safari" and version "3.2.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.2.1 Search vendor "Apple" for product "Safari" and version "3.2.1" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.2.2 Search vendor "Apple" for product "Safari" and version "3.2.2" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 3.2.3 Search vendor "Apple" for product "Safari" and version "3.2.3" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 4.0 Search vendor "Apple" for product "Safari" and version "4.0" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 4.0 Search vendor "Apple" for product "Safari" and version "4.0" | beta |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 4.0.0b Search vendor "Apple" for product "Safari" and version "4.0.0b" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 4.0.1 Search vendor "Apple" for product "Safari" and version "4.0.1" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
| Apple Search vendor "Apple" | Safari Search vendor "Apple" for product "Safari" | 4.0.2 Search vendor "Apple" for product "Safari" and version "4.0.2" | - |
Affected
| in | Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | * | - |
Safe
|
