« Volver al listado

CVE-2009-5097

Estado: ModificadaAlta (7.1)—

Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated by reading PalmDatabase.db3.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-5097",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-09-13T19:59:25.407",
  "references": [
    {
      "url": "http://kb.palm.com/wps/portal/kb/na/pre/p100eww/sprint/solutions/article/50607_en.html#12",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/36936",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://tlhsecurity.blogspot.com/2009/10/palm-pre-webos-11-remote-file-access.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.precentral.net/webos-1-2-fixed-serious-file-security-issue",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1022987",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://kb.palm.com/wps/portal/kb/na/pre/p100eww/sprint/solutions/article/50607_en.html#12",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/36936",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://tlhsecurity.blogspot.com/2009/10/palm-pre-webos-11-remote-file-access.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.precentral.net/webos-1-2-fixed-serious-file-security-issue",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1022987",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated by reading PalmDatabase.db3."
    },
    {
      "lang": "es",
      "value": "Palm Pre WebOS v1.1 y anteriores procesa el JavaScript en los mensajes de correo electrónico, lo que permite a atacantes remotos ejecutar código JavaScript de su elección, como lo demuestra la lectura de PalmDatabase.db3."
    }
  ],
  "lastModified": "2026-06-16T23:15:00.683",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hp:palm_pre_webos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26D8E6DF-FA92-4A14-8701-8049BA053F2E",
              "versionEndIncluding": "1.1.0"
            },
            {
              "criteria": "cpe:2.3:o:hp:palm_pre_webos:1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B50EAFC-68AC-4E87-9ADD-032C8432E6D1"
            },
            {
              "criteria": "cpe:2.3:o:hp:palm_pre_webos:1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A912CC8D-70EF-4D69-96D9-899D8B91CC3C"
            },
            {
              "criteria": "cpe:2.3:o:hp:palm_pre_webos:1.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07ABE032-0F75-446D-802C-8448D004DD3C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}