CVE-2009-1706
Summary
| CVE | CVE-2009-1706 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-06-10 18:00:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The Private Browsing feature in Apple Safari before 4.0 on Windows does not remove cookies from the alternate cookie store in unspecified circumstances upon (1) disabling of the feature or (2) exit of the application, which makes it easier for remote web servers to track users via a cookie. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Safari | 3.0 | - | windows | All |
| Application | Apple | Safari | 3.0.1 | - | windows | All |
| Application | Apple | Safari | 3.0.2 | - | windows | All |
| Application | Apple | Safari | 3.0.3 | - | windows | All |
| Application | Apple | Safari | 3.0.4 | - | windows | All |
| Application | Apple | Safari | 3.1 | - | windows | All |
| Application | Apple | Safari | 3.1.1 | - | windows | All |
| Application | Apple | Safari | 3.1.2 | - | windows | All |
| Application | Apple | Safari | 3.2 | - | windows | All |
| Application | Apple | Safari | 3.2.1 | - | windows | All |
| Application | Apple | Safari | 3.2.2 | - | windows | All |
| Application | Apple | Safari | All | - | windows | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About the security content of Safari 4.0 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Patch, Vendor Advisory |
| RETIRED: Apple Safari Prior to 4.0 Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| Apple Safari for Windows Private Browsing Cookie Data Local Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| osvdb.org/54997 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| APPLE-SA-2009-06-08-1 Safari 4.0 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Patch, Vendor Advisory |
| Apple Safari Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.