VDB
CVE-2009-0960
CVE-2009-0960
PUBLISHED
CVSS 4.300000190734863 MEDIUM
The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not provide an option to disable remote image loading in HTML email, which allows remote attackers to determine the device address and when an e-mail is read via an HTML email containing an image URL.
EPSS 1.89% · 78.8th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
1.89%
78.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | iphone_os | 2.0.2, 2.2, 2.0.1 |
| n/a | n/a | n/a |
| apple | ipod_touch |
Timeline
- Jun 19, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 12, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 29, 2023 EPSS Score
- Jul 21, 2023 EPSS Score
References
- ADV-2009-1621 vdb
- 35434 vdb
- 35414 vdb
- http://support.apple.com/kb/HT3639 url
- APPLE-SA-2009-06-17-1 vendor-advisory
- iphone-ipod-mail-weak-security(51209) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2009-0960 advisory