CVE-2009-2841
Description
The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality, aka rdar problem 7271202.
Risk Information
Base Score
8.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
3.879
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities affected in Apple Safari 4.0.3 | Windows |
| Multiple Vulnerabilities are affected in Apple Safari 3.2.3 | Windows |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 0.8 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 0.9 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.3.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.3.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.0.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.1.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 0.8 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 0.9 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.3.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.3.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.1.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.1.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.1.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2.4 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2.5 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0_pre | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0.3_417.9.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0.4_419.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.0.4_beta | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.1.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.2.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.2.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 4.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.2.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 2.0.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.2.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.2.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.2.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 4.0.0b | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 4.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.0.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.0.0b1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.0.0b2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.0.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.1.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.2.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 1.3.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 3.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 4.0.2 | Mac |
| Vulnerabilities CVE-2009-2816,CVE-2009-2841,CVE-2009-2842,CVE-2010-1119 are affected in Apple Safari 3.2.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari 4.0.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2.5 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2.4 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0_pre | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0.4_419.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.1.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0.3_417.9.3 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.0.4_beta | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0.0b1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0.0b2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.0.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.1.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.2.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 1.3.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 2.0.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 3.2.0 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 4.0.0b | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 4.0.1 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 4.0.2 | Mac |
| Multiple Vulnerabilities are affected in Apple Safari for MAC 4.0.3 | Mac |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
| PATCH-611604 | Apple Safari for MAC (MacOS Sonoma) (18.6) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234