CVE-2009-1724

N/A Unknown
Published: July 09, 2009 Modified: April 23, 2026
View on NVD

Description

Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors related to parent and top objects.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/55738
Source: cve@mitre.org
http://support.apple.com/kb/HT3666
Source: cve@mitre.org
Patch Vendor Advisory
http://www.securityfocus.com/bid/35441
Source: cve@mitre.org
Exploit
http://lists.apple.com/archives/security-announce/2009/Jul/msg00000.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://osvdb.org/55738
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/35758
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/36677
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/43068
Source: af854a3a-2127-422b-91ae-364da2661108
http://support.apple.com/kb/HT3666
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://support.apple.com/kb/HT3860
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/35441
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.securitytracker.com/id?1022525
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2009/1827
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2011/0212
Source: af854a3a-2127-422b-91ae-364da2661108

28 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
1.5%
81th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

apple