Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2007-2400


Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.


Published

2007-06-25T19:30:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79
    CWE-362

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System apple iphone_os ≤ 1.0 Yes
Operating System apple mac_os_x * No
Operating System microsoft windows_vista * No
Operating System microsoft windows_xp * No
Application apple safari 3.0 Yes
Application apple safari 3.0.1 Yes

References