Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-2797
Description:The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by reading Referer logs on a web server.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-2797
http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.html
BugTraq ID: 36339
http://www.securityfocus.com/bid/36339
http://www.mandriva.com/security/advisories?name=MDVSA-2011:039
http://secunia.com/advisories/36677
http://secunia.com/advisories/41856
http://secunia.com/advisories/43068
SuSE Security Announcement: SUSE-SR:2011:002 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html
http://www.ubuntu.com/usn/USN-1006-1
http://www.vupen.com/english/advisories/2010/2722
http://www.vupen.com/english/advisories/2011/0212
http://www.vupen.com/english/advisories/2011/0552
XForce ISS Database: ipod-ipone-referer-info-disclosure(53187)
https://exchange.xforce.ibmcloud.com/vulnerabilities/53187




© 1998-2025 E-Soft Inc. All rights reserved.