Vulnerability Description
Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | 1.2.4 |
References
- http://marc.info/?l=bugtraq&m=110756965213819&w=2
- http://securitytracker.com/id?1013087
- http://tigger.uic.edu/~jrockw2/safari_20050204.txtExploitVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19227
- http://marc.info/?l=bugtraq&m=110756965213819&w=2
- http://securitytracker.com/id?1013087
- http://tigger.uic.edu/~jrockw2/safari_20050204.txtExploitVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19227
FAQ
What is CVE-2005-0341?
CVE-2005-0341 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripti...
How severe is CVE-2005-0341?
CVE-2005-0341 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0341?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Safari.