Summary
This host is installed with Apple Safari Web Browser and is prone to multiple vulnerabilities.
Impact
Successful exploitation will let the attacker execute arbitrary code, bypass security restrictions, gain sensitive information and can cause Denial of Service.
Impact Level: System/Application
Solution
Upgrade to Safari version 4.0.3
http://www.apple.com/support/downloads
Insight
- An error in WebKit while parsing malicious floating point numbers can be exploited to cause buffer overflows.
- An unspecified error in the Top Sites feature can be exploited to place a malicious web site in the Top Sites view when a user visits a specially crafted web page.
- Incomplete blacklist vulnerability in WebKit can be exploited via unspecified homoglyphs.
- An error in WebKit in the handling of the 'pluginspage' attribute of the 'embed' element can be exploited to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document.
Affected
Apple Safari version prior to 4.0.3.
References
Severity
Classification
-
CVE CVE-2009-2195, CVE-2009-2196, CVE-2009-2199, CVE-2009-2200 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities