CVE-2007-3514
published 2007-07-03CVE-2007-3514: Cross-domain vulnerability in Apple Safari for Windows 3.0.2 allows remote attackers to bypass the Same Origin Policy and access restricted information from…
PriorityP427high8.5CVSS 2.0
AVNACLAuNCCIPAN
EPSS
1.33%
68.1th percentile
Cross-domain vulnerability in Apple Safari for Windows 3.0.2 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute to a file:// location, a different vector than CVE-2007-3482.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | — | — |
| vmware | esxi | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
Updated VirtualCenter addresses User Account Disclosure Vulnerability
vendor_vmware·2008-08-12·CVSS 5.0
CVE-2007-3514 [MEDIUM] Updated VirtualCenter addresses User Account Disclosure Vulnerability
VMSA-2008-0012: Updated VirtualCenter addresses User Account Disclosure Vulnerability
Updated VirtualCenter addresses User Account Disclosure Vulnerability 2. Relevant releases VirtualCenter 2.5 previous to Update 2 VirutalCenter 2.0.2 previous to Update 5 3. VirtualCenter User Account Disclosure Vulnerability An information disclosure vulnerability is present in VirtualCenter. Exploitation of this flaw might result in disclosure of the user names of system accounts. VMware would like to thank Brett Moore of Insomnia Security for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2008-3514 to this issue. VMware Product ============= Product Version ======= Running on ======= Replace with/ Apply Patch ================= VMw
GHSA
GHSA-f23g-mp7v-582j: Cross-domain vulnerability in Apple Safari for Windows 3
ghsa_unreviewed·2022-05-01·CVSS 7.8
CVE-2007-3514 [HIGH] GHSA-f23g-mp7v-582j: Cross-domain vulnerability in Apple Safari for Windows 3
Cross-domain vulnerability in Apple Safari for Windows 3.0.2 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute to a file:// location, a different vector than CVE-2007-3482.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2007-07-03
Published