VULNERABILITY INTELLIGENCE

CVE-2009-5097

CVSS score7.1 HIGH
EPSS probability1.89%
CISA KEVNot currently listed
Published2011-09-13
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:C/I:N/A:N

Description

Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated by reading PalmDatabase.db3.

Weakness classification

  • CWE-94: Improper Control of Generation of Code ('Code Injection')

Primary references