CVE-2009-3016
Apple Safari - XSS
Title source: ruleDescription
Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header.
Scores
EPSS
0.0028
EPSS Percentile
50.7%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
apple/safari
n/a/n/a
Timeline
Published
Aug 31, 2009
Tracked Since
Feb 18, 2026