Loading...
Loading...
Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.
June 15, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-2058
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.