{"api_version":"1","generated_at":"2026-07-23T09:19:03+00:00","cve":"CVE-2009-2797","urls":{"html":"https://cve.report/CVE-2009-2797","api":"https://cve.report/api/cve/CVE-2009-2797.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-2797","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-2797"},"summary":{"title":"CVE-2009-2797","description":"The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by reading Referer logs on a web server.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-09-10 21:30:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/43068","name":"http://secunia.com/advisories/43068","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"SUSE update for Multiple Packages - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36677","name":"http://secunia.com/advisories/36677","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Apple iPhone /  iPod touch Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT3860","name":"http://support.apple.com/kb/HT3860","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"About the security content of iPhone OS 3.1 and iPhone OS 3.1.1 for iPod touch","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/2722","name":"http://www.vupen.com/english/advisories/2010/2722","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0212","name":"http://www.vupen.com/english/advisories/2011/0212","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/41856","name":"http://secunia.com/advisories/41856","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Ubuntu update for webkit - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:039","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:039","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support / Security / Advisories /  / MDVSA-2011:039 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html","name":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2011:002","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53187","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53187","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/36339","name":"http://www.securityfocus.com/bid/36339","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Apple iPhone and iPod touch Safari Referer Header Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.ubuntu.com/usn/USN-1006-1","name":"http://www.ubuntu.com/usn/USN-1006-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-1006-1: WebKit vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.html","name":"http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch","Vendor Advisory"],"title":"APPLE-SA-2009-09-09-1 iPhone OS 3.1 and iPhone OS 3.1.1 for iPod\ttouch","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0552","name":"http://www.vupen.com/english/advisories/2011/0552","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-2797","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-2797","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"2797","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2797","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"ipod_touch","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2797","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"10.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"lts","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2797","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"10.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2797","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"9.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:07:35.913Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"MDVSA-2011:039","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:039"},{"name":"ADV-2010-2722","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/2722"},{"name":"43068","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43068"},{"name":"USN-1006-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-1006-1"},{"name":"41856","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/41856"},{"name":"ADV-2011-0212","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0212"},{"name":"ipod-ipone-referer-info-disclosure(53187)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53187"},{"name":"SUSE-SR:2011:002","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html"},{"name":"ADV-2011-0552","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0552"},{"name":"36339","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36339"},{"name":"APPLE-SA-2009-09-09-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.html"},{"name":"36677","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36677"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT3860"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-09-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by reading Referer logs on a web server."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"MDVSA-2011:039","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:039"},{"name":"ADV-2010-2722","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/2722"},{"name":"43068","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43068"},{"name":"USN-1006-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/USN-1006-1"},{"name":"41856","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/41856"},{"name":"ADV-2011-0212","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0212"},{"name":"ipod-ipone-referer-info-disclosure(53187)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53187"},{"name":"SUSE-SR:2011:002","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html"},{"name":"ADV-2011-0552","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0552"},{"name":"36339","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36339"},{"name":"APPLE-SA-2009-09-09-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.html"},{"name":"36677","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36677"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT3860"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-2797","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by reading Referer logs on a web server."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"MDVSA-2011:039","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2011:039"},{"name":"ADV-2010-2722","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/2722"},{"name":"43068","refsource":"SECUNIA","url":"http://secunia.com/advisories/43068"},{"name":"USN-1006-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/USN-1006-1"},{"name":"41856","refsource":"SECUNIA","url":"http://secunia.com/advisories/41856"},{"name":"ADV-2011-0212","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0212"},{"name":"ipod-ipone-referer-info-disclosure(53187)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53187"},{"name":"SUSE-SR:2011:002","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html"},{"name":"ADV-2011-0552","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0552"},{"name":"36339","refsource":"BID","url":"http://www.securityfocus.com/bid/36339"},{"name":"APPLE-SA-2009-09-09-1","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2009/Sep/msg00001.html"},{"name":"36677","refsource":"SECUNIA","url":"http://secunia.com/advisories/36677"},{"name":"http://support.apple.com/kb/HT3860","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT3860"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-2797","datePublished":"2009-09-10T21:00:00.000Z","dateReserved":"2009-08-17T00:00:00.000Z","dateUpdated":"2024-08-07T06:07:35.913Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-09-10 21:30:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionEndExcluding":"3.1","matchCriteriaId":"FF765D52-58F5-49F1-8323-2EB7EB5006A5"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:ipod_touch:*:*","versionEndExcluding":"3.1.1","matchCriteriaId":"3935C1A3-3488-465C-ADE2-DC6B31365DC0"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*","matchCriteriaId":"A2BCB73E-27BB-4878-AD9C-90C4F20C25A0"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:*","matchCriteriaId":"5D37DF0F-F863-45AC-853A-3E04F9FEC7CA"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*","matchCriteriaId":"87614B58-24AB-49FB-9C84-E8DDBA16353B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"2797","Ordinal":"1","Title":"CVE-2009-2797","CVE":"CVE-2009-2797","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"2797","Ordinal":"1","NoteData":"The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by reading Referer logs on a web server.","Type":"Description","Title":"CVE-2009-2797"},{"CveYear":"2009","CveId":"2797","Ordinal":"2","NoteData":"2009-09-10","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"2797","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}