Apple Safari before 4.0.5 on Windows does not properly validate external URL schemes, which allows remote attackers to open local files and execute arbitrary code via a crafted HTML document.
| Software | From | Fixed in |
|---|---|---|
| apple / safari | - | 4.0.4.x |
| apple / safari | 4.0-beta | 4.0-beta.x |
| apple / safari | 4.0 | 4.0.x |
| apple / safari | 4.0.1 | 4.0.1.x |
| apple / safari | 4.0.2 | 4.0.2.x |
| apple / safari | 4.0.3 | 4.0.3.x |