Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2007-3758


Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and in Mac OS X 10.4 through 10.4.10, allows remote attackers to set Javascript window properties for web pages that are in a different domain, which can be leveraged to conduct cross-site scripting (XSS) attacks.


Published

2007-09-27T22:17:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System apple iphone_os 1.1.1 No
Application apple safari * Yes
Operating System apple mac_os_x 10.4 No
Operating System apple mac_os_x 10.4.1 No
Operating System apple mac_os_x 10.4.2 No
Operating System apple mac_os_x 10.4.3 No
Operating System apple mac_os_x 10.4.4 No
Operating System apple mac_os_x 10.4.5 No
Operating System apple mac_os_x 10.4.6 No
Operating System apple mac_os_x 10.4.7 No
Operating System apple mac_os_x 10.4.8 No
Operating System apple mac_os_x 10.4.9 No
Operating System apple mac_os_x 10.4.10 No
Operating System microsoft windows_vista * No
Operating System microsoft windows_xp * No
Application apple safari ≤ 3.0.3 Yes

References