peter bassill · operator
$ cve CVE-2009-0162 JSON

CVE-2009-0162 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 5.4% (pctl 92)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote attackers to inject arbitrary web script or HTML via a crafted feed: URL.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS5.35% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2009-05-13
Last modified2026-06-16

Affected (5)

VendorProduct
applemac os x
applemac os x server
applesafari
microsoftwindows vista
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD