peter bassill · operator
$ cve CVE-2011-0167 JSON

CVE-2011-0167 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 3.3% (pctl 88)

Patch early

A public exploit exists.

Description

The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Policy, and force the upload of arbitrary local files from a client computer, via a crafted web site.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS3.34% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2011-03-11
Last modified2026-06-16

Affected (2)

VendorProduct
applesafari
applewebkit

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD