[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-2400Date: (C)2007-06-25   (M)2023-12-22


Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.3
Exploit Score: 8.6
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECTRACK-1018282
BID-24599
SECUNIA-26287
OSVDB-36452
ADV-2007-2316
ADV-2007-2731
APPLE-SA-2007-06-22
VU#289988
http://docs.info.apple.com/article.html?artnum=306173

CPE    3
cpe:/o:apple:mac_os_x
cpe:/o:microsoft:windows_xp
cpe:/o:microsoft:windows_vista
CWE    1
CWE-79

© SecPod Technologies