« Volver al listado

CVE-2009-0960

Estado: ModificadaMedia (4.3)—

The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not provide an option to disable remote image loading in HTML email, which allows remote attackers to determine the device address and when an e-mail is read via an HTML email containing an image URL.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-0960",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-06-19T16:30:00.280",
  "references": [
    {
      "url": "http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.apple.com/kb/HT3639",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/35414",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/35434",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1621",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51209",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.apple.com/kb/HT3639",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/35414",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/35434",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/1621",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51209",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not provide an option to disable remote image loading in HTML email, which allows remote attackers to determine the device address and when an e-mail is read via an HTML email containing an image URL."
    },
    {
      "lang": "es",
      "value": "El componente Mail en iPhone OS versiones 1.0 hasta 2.2.1 y iPhone OS para iPod touch versiones 1.1 hasta 2.2.1, de Apple, no proporciona una opción para deshabilitar la carga remota de imágenes en el correo electrónico HTML, lo que permite a los atacantes remotos determinar la dirección del dispositivo y cuando se lee un correo electrónico por medio de un correo electrónico HTML que contiene una URL de imagen."
    }
  ],
  "lastModified": "2026-06-16T23:06:12.477",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7B6D035-38A9-4C0B-9A9D-CAE3BF1CA56D"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C5B94E7-2C24-4913-B65E-8D8A0DE2B80B"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E28FB0CB-D636-4F85-B5F7-70EC30053925"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9EC16D1C-065A-4D1A-BA6E-528A71DF65CC"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27319629-171F-42AA-A95F-2D71F78097D0"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F7AEFAB-7BB0-40D8-8BA5-71B374EB69DB"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "297F9438-0F04-4128-94A8-A504B600929E"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8618621-F871-4531-9F6C-7D60F2BF8B75"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "824DED2D-FA1D-46FC-8252-6E25546DAE29"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1641DDFA-3BF1-467F-8EC3-98114FF9F07B"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF40CDA4-4716-4815-9ED0-093FE266734C"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D61644E2-7AF5-48EF-B3D5-59C7B2AD1A58"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D06D54D-97FD-49FD-B251-CC86FBA68CA6"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25A5D868-0016-44AB-80E6-E5DF91F15455"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C14EEA4-6E35-4EBE-9A43-8F6D69318BA0"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B15E90AE-2E15-4BC2-B0B8-AFA2B1297B03"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E0C0A8D-3DDD-437A-BB3D-50FAEAF6C440"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "340C4071-1447-477F-942A-8E09EA29F917"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9EC16D1C-065A-4D1A-BA6E-528A71DF65CC"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27319629-171F-42AA-A95F-2D71F78097D0"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F7AEFAB-7BB0-40D8-8BA5-71B374EB69DB"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "297F9438-0F04-4128-94A8-A504B600929E"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8618621-F871-4531-9F6C-7D60F2BF8B75"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "824DED2D-FA1D-46FC-8252-6E25546DAE29"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1641DDFA-3BF1-467F-8EC3-98114FF9F07B"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF40CDA4-4716-4815-9ED0-093FE266734C"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D61644E2-7AF5-48EF-B3D5-59C7B2AD1A58"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D06D54D-97FD-49FD-B251-CC86FBA68CA6"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25A5D868-0016-44AB-80E6-E5DF91F15455"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C14EEA4-6E35-4EBE-9A43-8F6D69318BA0"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B15E90AE-2E15-4BC2-B0B8-AFA2B1297B03"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E0C0A8D-3DDD-437A-BB3D-50FAEAF6C440"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:apple:ipod_touch:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88FA2602-DDAB-4E23-A3D2-FB712970AAD1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}