peter bassill · operator
$ cve CVE-2009-1699 JSON

CVE-2009-1699 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 29.1% (pctl 98)

Patch early

A public exploit exists.

Description

The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS29.1% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-611
On CISA KEVno
Public exploityes
Published2009-06-10
Last modified2026-06-16

Affected (4)

VendorProduct
appleiphone os
applesafari
canonicalubuntu linux
opensuseopensuse

Public exploits

SourceTitleDate
exploit-dbWebKit - XML External Entity Information Disclosure2009-05-08

References

→ the Explorer  ·  watch your stack  ·  NVD