CVE-2011-3230 describes a critical vulnerability in Apple Safari before version 5.1.1 on Mac OS X, where the browser fails to properly enforce security policies for "file:" URLs. This flaw allows remote attackers to execute arbitrary code on a user's system simply by enticing them to visit a specially crafted website. The vulnerability carries a CVSS score of 6.8 (Medium) with a high FAUCET Risk Score of 99/100, indicating a significant potential impact including partial compromise of confidentiality, integrity, and availability, achievable with medium attack complexity over a network. While not listed in CISA's KEV catalog, exploit code is publicly available through Metasploit (EDB-17986), and the vulnerability has garnered community discussion and media coverage, suggesting awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
<= 5.1CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:1.0:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:1.0:beta:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:apple:safari:1.0:beta2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.