{"api_version":"1","generated_at":"2026-07-23T10:47:23+00:00","cve":"CVE-2009-1699","urls":{"html":"https://cve.report/CVE-2009-1699","api":"https://cve.report/api/cve/CVE-2009-1699.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-1699","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-1699"},"summary":{"title":"CVE-2009-1699","description":"The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an \"XXE attack.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2009-06-10 18:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-611","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.1","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:N/A:N","baseScore":7.1,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://support.apple.com/kb/HT3639","name":"http://support.apple.com/kb/HT3639","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About the security content of iPhone OS 3.0 Software Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/43068","name":"http://secunia.com/advisories/43068","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"SUSE update for Multiple Packages - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT3613","name":"http://support.apple.com/kb/HT3613","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"About the security content of Safari 4.0","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0212","name":"http://www.vupen.com/english/advisories/2011/0212","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/35260","name":"http://www.securityfocus.com/bid/35260","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Third Party Advisory","VDB Entry"],"title":"RETIRED: Apple Safari Prior to 4.0 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.exploit-db.com/exploits/8907","name":"https://www.exploit-db.com/exploits/8907","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Apple Safari <= 3.2.x (XXE attack) Local File Theft Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/1621","name":"http://www.vupen.com/english/advisories/2009/1621","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html","name":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2011:002","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://scary.beasts.org/security/CESA-2009-006.html","name":"http://scary.beasts.org/security/CESA-2009-006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"CESA-2009-006 - rev 1","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/54972","name":"http://osvdb.org/54972","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.ubuntu.com/usn/USN-857-1","name":"http://www.ubuntu.com/usn/USN-857-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-857-1: Qt vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html","name":"http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"APPLE-SA-2009-06-17-1 iPhone OS 3.0 Software Update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://scarybeastsecurity.blogspot.com/2009/06/apples-safari-4-fixes-local-file-theft.html","name":"http://scarybeastsecurity.blogspot.com/2009/06/apples-safari-4-fixes-local-file-theft.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Security: Apple's Safari 4 fixes local file theft attack","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html","name":"http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Mailing List","Patch","Vendor Advisory"],"title":"APPLE-SA-2009-06-08-1 Safari 4.0","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/35379","name":"http://secunia.com/advisories/35379","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Apple Safari Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/1522","name":"http://www.vupen.com/english/advisories/2009/1522","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/35321","name":"http://www.securityfocus.com/bid/35321","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"WebKit XML External Entity Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-1699","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1699","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"1699","vulnerable":"1","versionEndIncluding":"2.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1699","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"safari","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1699","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"8.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1699","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"9.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1699","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"opensuse","cpe6":"11.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1699","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"opensuse","cpe6":"11.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:20:35.119Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT3639"},{"name":"43068","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43068"},{"name":"ADV-2009-1621","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/1621"},{"name":"8907","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/8907"},{"name":"ADV-2011-0212","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0212"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://scary.beasts.org/security/CESA-2009-006.html"},{"name":"APPLE-SA-2009-06-08-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html"},{"name":"54972","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/54972"},{"name":"35260","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/35260"},{"name":"ADV-2009-1522","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/1522"},{"name":"APPLE-SA-2009-06-17-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html"},{"name":"SUSE-SR:2011:002","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html"},{"name":"35379","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35379"},{"name":"USN-857-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-857-1"},{"name":"35321","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/35321"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://scarybeastsecurity.blogspot.com/2009/06/apples-safari-4-fixes-local-file-theft.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT3613"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-06-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an \"XXE attack.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT3639"},{"name":"43068","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43068"},{"name":"ADV-2009-1621","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/1621"},{"name":"8907","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/8907"},{"name":"ADV-2011-0212","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0212"},{"tags":["x_refsource_MISC"],"url":"http://scary.beasts.org/security/CESA-2009-006.html"},{"name":"APPLE-SA-2009-06-08-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html"},{"name":"54972","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/54972"},{"name":"35260","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/35260"},{"name":"ADV-2009-1522","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/1522"},{"name":"APPLE-SA-2009-06-17-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html"},{"name":"SUSE-SR:2011:002","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html"},{"name":"35379","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35379"},{"name":"USN-857-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-857-1"},{"name":"35321","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/35321"},{"tags":["x_refsource_MISC"],"url":"http://scarybeastsecurity.blogspot.com/2009/06/apples-safari-4-fixes-local-file-theft.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT3613"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-1699","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an \"XXE attack.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://support.apple.com/kb/HT3639","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT3639"},{"name":"43068","refsource":"SECUNIA","url":"http://secunia.com/advisories/43068"},{"name":"ADV-2009-1621","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/1621"},{"name":"8907","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/8907"},{"name":"ADV-2011-0212","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0212"},{"name":"http://scary.beasts.org/security/CESA-2009-006.html","refsource":"MISC","url":"http://scary.beasts.org/security/CESA-2009-006.html"},{"name":"APPLE-SA-2009-06-08-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html"},{"name":"54972","refsource":"OSVDB","url":"http://osvdb.org/54972"},{"name":"35260","refsource":"BID","url":"http://www.securityfocus.com/bid/35260"},{"name":"ADV-2009-1522","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/1522"},{"name":"APPLE-SA-2009-06-17-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2009/Jun/msg00005.html"},{"name":"SUSE-SR:2011:002","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html"},{"name":"35379","refsource":"SECUNIA","url":"http://secunia.com/advisories/35379"},{"name":"USN-857-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-857-1"},{"name":"35321","refsource":"BID","url":"http://www.securityfocus.com/bid/35321"},{"name":"http://scarybeastsecurity.blogspot.com/2009/06/apples-safari-4-fixes-local-file-theft.html","refsource":"MISC","url":"http://scarybeastsecurity.blogspot.com/2009/06/apples-safari-4-fixes-local-file-theft.html"},{"name":"http://support.apple.com/kb/HT3613","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT3613"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-1699","datePublished":"2009-06-10T17:37:00.000Z","dateReserved":"2009-05-20T00:00:00.000Z","dateUpdated":"2024-08-07T05:20:35.119Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-06-10 18:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-611","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:N/A:N","baseScore":7.1,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","versionEndExcluding":"4.0","matchCriteriaId":"212BF588-5C81-4801-A76D-73FB1DE211EA"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionStartIncluding":"1.0.0","versionEndIncluding":"2.2.1","matchCriteriaId":"614C28E3-3645-4B20-95E5-42E7F123ADDB"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*","matchCriteriaId":"4747CC68-FAF4-482F-929A-9DA6C24CB663"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*","matchCriteriaId":"A5D026D0-EF78-438D-BEDD-FC8571F3ACEB"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.2:*:*:*:*:*:*:*","matchCriteriaId":"A01C8B7E-EB19-40EA-B1D2-9AE5EA536C95"},{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*","matchCriteriaId":"5646FDE9-CF21-46A9-B89D-F5BBDB4249AF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"1699","Ordinal":"1","Title":"CVE-2009-1699","CVE":"CVE-2009-1699","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"1699","Ordinal":"1","NoteData":"The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an \"XXE attack.\"","Type":"Description","Title":"CVE-2009-1699"},{"CveYear":"2009","CveId":"1699","Ordinal":"2","NoteData":"2009-06-10","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"1699","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}