CVE-2009-0960
Summary
| CVE | CVE-2009-0960 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-06-19 16:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not provide an option to disable remote image loading in HTML email, which allows remote attackers to determine the device address and when an e-mail is read via an HTML email containing an image URL. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Iphone Os | All | All | All | All |
| Operating System | Apple | Iphone Os | 1.0.0 | All | All | All |
| Operating System | Apple | Iphone Os | 1.0.1 | All | All | All |
| Operating System | Apple | Iphone Os | 1.0.2 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.0 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.1 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.2 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.3 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.4 | All | All | All |
| Operating System | Apple | Iphone Os | 1.1.5 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0.0 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0.1 | All | All | All |
| Operating System | Apple | Iphone Os | 2.0.2 | All | All | All |
| Operating System | Apple | Iphone Os | 2.1 | All | All | All |
| Operating System | Apple | Iphone Os | 2.1.1 | All | All | All |
| Operating System | Apple | Iphone Os | 2.2 | All | All | All |
| Operating System | Apple | Iphone Os | 2.2.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About the security content of iPhone OS 3.0 Software Update | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Patch, Vendor Advisory |
| RETIRED: Apple iPhone and iPod touch Prior to Version 3.0 Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Apple iPhone and iPod touch Mail Client Information Disclosure Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| APPLE-SA-2009-06-17-1 iPhone OS 3.0 Software Update | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.