Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.
2009-06-15T19:30:05.530
2025-04-09T00:30:58.490
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apple | safari | ≤ 3.2.1 | Yes |
Application | apple | safari | 0.8 | Yes |
Application | apple | safari | 0.9 | Yes |
Application | apple | safari | 1.0 | Yes |
Application | apple | safari | 1.0 | Yes |
Application | apple | safari | 1.0 | Yes |
Application | apple | safari | 1.0.0 | Yes |
Application | apple | safari | 1.0.0b1 | Yes |
Application | apple | safari | 1.0.0b2 | Yes |
Application | apple | safari | 1.0.1 | Yes |
Application | apple | safari | 1.0.2 | Yes |
Application | apple | safari | 1.0.3 | Yes |
Application | apple | safari | 1.0.3 | Yes |
Application | apple | safari | 1.0.3 | Yes |
Application | apple | safari | 1.1 | Yes |
Application | apple | safari | 1.1.0 | Yes |
Application | apple | safari | 1.1.1 | Yes |
Application | apple | safari | 1.2 | Yes |
Application | apple | safari | 1.2.0 | Yes |
Application | apple | safari | 1.2.1 | Yes |
Application | apple | safari | 1.2.2 | Yes |
Application | apple | safari | 1.2.3 | Yes |
Application | apple | safari | 1.2.4 | Yes |
Application | apple | safari | 1.2.5 | Yes |
Application | apple | safari | 1.3 | Yes |
Application | apple | safari | 1.3.0 | Yes |
Application | apple | safari | 1.3.1 | Yes |
Application | apple | safari | 1.3.2 | Yes |
Application | apple | safari | 1.3.2 | Yes |
Application | apple | safari | 1.3.2 | Yes |
Application | apple | safari | 2 | Yes |
Application | apple | safari | 2.0 | Yes |
Application | apple | safari | 2.0.0 | Yes |
Application | apple | safari | 2.0.1 | Yes |
Application | apple | safari | 2.0.2 | Yes |
Application | apple | safari | 2.0.3 | Yes |
Application | apple | safari | 2.0.3 | Yes |
Application | apple | safari | 2.0.3 | Yes |
Application | apple | safari | 2.0.3 | Yes |
Application | apple | safari | 2.0.3 | Yes |
Application | apple | safari | 2.0.3_417.9.3 | Yes |
Application | apple | safari | 2.0.4 | Yes |
Application | apple | safari | 2.0.4_419.3 | Yes |
Application | apple | safari | 2.0_pre | Yes |
Application | apple | safari | 3 | Yes |
Application | apple | safari | 3.0 | Yes |
Application | apple | safari | 3.0.0 | Yes |
Application | apple | safari | 3.0.0b | Yes |
Application | apple | safari | 3.0.1 | Yes |
Application | apple | safari | 3.0.1 | Yes |
Application | apple | safari | 3.0.1b | Yes |
Application | apple | safari | 3.0.2 | Yes |
Application | apple | safari | 3.0.2b | Yes |
Application | apple | safari | 3.0.3 | Yes |
Application | apple | safari | 3.0.3 | Yes |
Application | apple | safari | 3.0.3b | Yes |
Application | apple | safari | 3.0.4 | Yes |
Application | apple | safari | 3.0.4_beta | Yes |
Application | apple | safari | 3.0.4b | Yes |
Application | apple | safari | 3.1 | Yes |
Application | apple | safari | 3.1.0 | Yes |
Application | apple | safari | 3.1.0b | Yes |
Application | apple | safari | 3.1.1 | Yes |
Application | apple | safari | 3.1.2 | Yes |
Application | apple | safari | 3.2 | Yes |
Application | apple | safari | 3.2.0 | Yes |