CVE-2009-2816
Description
The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page.
Risk Information
Base Score
8.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
2.154
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Updates for Google Chrome (66.0.3359.170) | Windows |
| Updates for Google Chrome (x64) (66.0.3359.170) | Windows |
| Updates for Google Chrome (66.0.3359.181) | Windows |
| Updates for Google Chrome (x64) (66.0.3359.181) | Windows |
| Updates for Google Chrome (67.0.3396.62) | Windows |
| Updates for Google Chrome (x64) (67.0.3396.62) | Windows |
| Updates for Google Chrome (67.0.3396.79) | Windows |
| Updates for Google Chrome (x64) (67.0.3396.79) | Windows |
| Updates for Google Chrome (67.0.3396.87) | Windows |
| Updates for Google Chrome (x64) (67.0.3396.87) | Windows |
| Google Chrome (67.0.3396.99) | Windows |
| Google Chrome (x64) (67.0.3396.99) | Windows |
| Vulnerabilities CVE-2009-2816,CVE-2009-3456,CVE-2009-3931,CVE-2009-3932,CVE-2009-3934 are affected in Chrome (x64) 3.0.195.21(x64) | Windows |
| Vulnerabilities CVE-2009-2816,CVE-2009-3456,CVE-2009-3931,CVE-2009-3932,CVE-2009-3934 are affected in Chrome 3.0.195.21 | Windows |
| Multiple Vulnerabilities are affected in Apple Safari 3.2.3 | Windows |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 0.8 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 0.9 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.3.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.3.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.0.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.1.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 0.8 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 0.9 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.3.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.3.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.1.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.1.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.1.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2.4 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2.5 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0_pre | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0.3_417.9.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0.4_419.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.0.4_beta | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.1.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.2.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.2.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 4.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.2.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.2.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.2.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.2.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 4.0.0b | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 4.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.0.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.0.0b1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.0.0b2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.0.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.1.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.3.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 4.0.2 | Mac |
| Vulnerabilities CVE-2009-2816,CVE-2009-2841,CVE-2009-2842,CVE-2010-1119 are affected in Apple Safari 3.2.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 4.0.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2.5 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2.4 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0_pre | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0.4_419.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.1.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0.3_417.9.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.0.4_beta | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0.0b1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0.0b2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.1.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.3.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.2.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 4.0.0b | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 4.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 4.0.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 4.0.3 | Mac |
| Updates for Google Chrome (66.0.3359.170) (For Ubuntu) | Linux |
| Updates for Google Chrome (66.0.3359.170) (For Debian) | Linux |
| Updates for Google Chrome (66.0.3359.181) (For Debian) | Linux |
| Updates for Google Chrome (67.0.3396.62) (For Debian) | Linux |
| Updates for Google Chrome (67.0.3396.79) (For Debian) | Linux |
| Updates for Google Chrome (67.0.3396.87) (For Debian) | Linux |
| Google Chrome (67.0.3396.99) (For Debian) | Linux |
| Vulnerabilities CVE-2009-2816,CVE-2009-3456,CVE-2009-3931,CVE-2009-3932,CVE-2009-3934 are affected in Chrome 3.0.195.21 (For Debian) | Linux |
| Updates for Google Chrome (66.0.3359.170) (For Centos) | Linux |
| Updates for Google Chrome (66.0.3359.181) (For Centos) | Linux |
| Updates for Google Chrome (67.0.3396.62) (For Centos) | Linux |
| Updates for Google Chrome (67.0.3396.79) (For Centos) | Linux |
| Updates for Google Chrome (67.0.3396.87) (For Centos) | Linux |
| Google Chrome (67.0.3396.99) (For Centos) | Linux |
| Vulnerabilities CVE-2009-2816,CVE-2009-3456,CVE-2009-3931,CVE-2009-3932,CVE-2009-3934 are affected in Chrome 3.0.195.21 (For Centos) | Linux |
| Updates for Google Chrome (66.0.3359.170) (For RedHat) | Linux |
| Updates for Google Chrome (66.0.3359.181) (For RedHat) | Linux |
| Updates for Google Chrome (67.0.3396.62) (For RedHat) | Linux |
| Updates for Google Chrome (67.0.3396.79) (For RedHat) | Linux |
| Updates for Google Chrome (67.0.3396.87) (For RedHat) | Linux |
| Google Chrome (67.0.3396.99) (For RedHat) | Linux |
| Vulnerabilities CVE-2009-2816,CVE-2009-3456,CVE-2009-3931,CVE-2009-3932,CVE-2009-3934 are affected in Chrome 3.0.195.21 (For RedHat) | Linux |
| Updates for Google Chrome (66.0.3359.170) (For Suse) | Linux |
| Updates for Google Chrome (66.0.3359.181) (For Suse) | Linux |
| Updates for Google Chrome (67.0.3396.62) (For Suse) | Linux |
| Updates for Google Chrome (67.0.3396.79) (For Suse) | Linux |
| Updates for Google Chrome (67.0.3396.87) (For Suse) | Linux |
| Google Chrome (67.0.3396.99) (For Suse) | Linux |
| Vulnerabilities CVE-2009-2816,CVE-2009-3456,CVE-2009-3931,CVE-2009-3932,CVE-2009-3934 are affected in Chrome 3.0.195.21 (For Suse) | Linux |
| Updates for Google Chrome (66.0.3359.181) (For Ubuntu) | Linux |
| Updates for Google Chrome (67.0.3396.62) (For Ubuntu) | Linux |
| Updates for Google Chrome (67.0.3396.79) (For Ubuntu) | Linux |
| Updates for Google Chrome (67.0.3396.87) (For Ubuntu) | Linux |
| Google Chrome (67.0.3396.99) (For Ubuntu) | Linux |
| Vulnerabilities CVE-2009-2816,CVE-2009-3456,CVE-2009-3931,CVE-2009-3932,CVE-2009-3934 are affected in Chrome 3.0.195.21 (For Ubuntu) | Linux |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-307513 | Updates for Google Chrome (66.0.3359.170) |
| PATCH-307515 | Updates for Google Chrome (x64) (66.0.3359.170) |
| PATCH-307534 | Updates for Google Chrome (66.0.3359.181) |
| PATCH-307535 | Updates for Google Chrome (x64) (66.0.3359.181) |
| PATCH-307607 | Updates for Google Chrome (67.0.3396.62) |
| PATCH-307608 | Updates for Google Chrome (x64) (67.0.3396.62) |
| PATCH-307641 | Updates for Google Chrome (67.0.3396.79) |
| PATCH-307644 | Updates for Google Chrome (x64) (67.0.3396.79) |
| PATCH-307660 | Updates for Google Chrome (67.0.3396.87) |
| PATCH-307662 | Updates for Google Chrome (x64) (67.0.3396.87) |
| PATCH-307715 | Google Chrome (67.0.3396.99) |
| PATCH-307716 | Google Chrome (x64) (67.0.3396.99) |
| PATCH-313162 | Google Chrome (x64) (80.0.3987.132) |
| PATCH-313161 | Google Chrome (80.0.3987.132) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234