CVE-2008-1007
published 2008-03-19CVE-2008-1007: WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.80%
85.0th percentile
WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 3.0.4 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-1563 wireshark: crash in SCCP dissector
bugzilla·2008-04-01·CVSS 4.3
CVE-2008-1563 [MEDIUM] CVE-2008-1563 wireshark: crash in SCCP dissector
CVE-2008-1563 wireshark: crash in SCCP dissector
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-1563 to the following vulnerability:
The "decode as" feature in packet-bssap.c in the SCCP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
References:
http://www.wireshark.org/security/wnpa-sec-2008-02.html
http://www.securityfocus.com/bid/28485
http://www.frsirt.com/english/advisories/2008/1007/references
http://secunia.com/advisories/29569
Discussion:
wireshark-1.0.0-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
wireshark-1.0.0-1.fc8 has been pushed to the Fedora 8 sta
Bugzilla
CVE-2008-1562 wireshark: crash in LDAP dissector
bugzilla·2008-04-01·CVSS 5.0
CVE-2008-1562 [MEDIUM] CVE-2008-1562 wireshark: crash in LDAP dissector
CVE-2008-1562 wireshark: crash in LDAP dissector
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-1562 to the following vulnerability:
The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740.
Refences:
http://www.wireshark.org/security/wnpa-sec-2008-02.html
http://www.securityfocus.com/bid/28485
http://www.frsirt.com/english/advisories/2008/1007/references
http://secunia.com/advisories/29569
Discussion:
wireshark-1.0.0-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this bug report.
---
wireshark-1.0.0-1.fc8 has been pushed to the Fedora 8 stabl
Bugzilla
CVE-2008-1561 wireshark: crash in X.509sat and Roofnet dissectors
bugzilla·2008-04-01·CVSS 5.0
CVE-2008-1561 [MEDIUM] CVE-2008-1561 wireshark: crash in X.509sat and Roofnet dissectors
CVE-2008-1561 wireshark: crash in X.509sat and Roofnet dissectors
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-1561 to the following vulnerability:
Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (application crash) via a malformed packet to the (1) X.509sat or (2) Roofnet dissectors. NOTE: Vector 2 might also lead to a hang.
Refences:
http://www.wireshark.org/security/wnpa-sec-2008-02.html
http://www.securityfocus.com/bid/28485
http://www.frsirt.com/english/advisories/2008/1007/references
http://secunia.com/advisories/29569
Discussion:
wireshark-1.0.0-1.fc7 has been pushed to the Fedora 7 stable repository. If problems still persist, please make note of it in this b
http://docs.info.apple.com/article.html?artnum=307563http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.htmlhttp://secunia.com/advisories/29393http://www.securityfocus.com/bid/28290http://www.securityfocus.com/bid/28335http://www.securitytracker.com/id?1019653http://www.us-cert.gov/cas/techalerts/TA08-079A.htmlhttp://www.vupen.com/english/advisories/2008/0920/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41324http://docs.info.apple.com/article.html?artnum=307563http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.htmlhttp://secunia.com/advisories/29393http://www.securityfocus.com/bid/28290http://www.securityfocus.com/bid/28335http://www.securitytracker.com/id?1019653http://www.us-cert.gov/cas/techalerts/TA08-079A.htmlhttp://www.vupen.com/english/advisories/2008/0920/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41324
2008-03-19
Published