CVE-2009-5097

Published Sep 13, 2011

Last updated 2 days ago

Overview

Description
Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated by reading PalmDatabase.db3.
Source
cve@mitre.org
NVD status
Deferred

Risk scores

CVSS 2.0

Type
Primary
Base score
7.1
Impact score
6.9
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:C/I:N/A:N

Weaknesses

nvd@nist.gov
CWE-94

Social media

Hype score
Not currently trending

Configurations