CVE-2007-2400Cross-site Scripting in Apple Iphone OS

Severity
4.3MEDIUMNVD
EPSS
0.5%
top 36.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 25
Latest updateMay 1

Description

Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDapple/safari3.0, 3.0.1+1

Patches

🔴Vulnerability Details

1
GHSA
GHSA-fgwf-g47p-3m7h: Race condition in Apple Safari 3 Beta before 32022-05-01