CVE-2009-1714
Apple Safari < 4.0_beta - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to the improper escaping of HTML attributes.
References (14)
Scores
EPSS
0.0065
EPSS Percentile
70.5%
Classification
CWE
CWE-79
Status
published
Affected Products (35)
apple/safari
< 4.0_beta
apple/safari
apple/safari
apple/safari
apple/safari
apple/safari
apple/safari
apple/safari
apple/safari
apple/safari
apple/safari
apple/safari
apple/safari
apple/safari
apple/safari
... and 20 more
Timeline
Published
Jun 10, 2009
Tracked Since
Feb 18, 2026