CVE

Id
39148  
CVE No.
CVE-2009-1713  
Status
Candidate  
Description
The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors.  
Phase
Assigned (20090520)  
Votes
None (candidate not yet proposed)  
Comments