CVE-2007-2400
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.
Una condición de carrera en Apple Safari versiones 3 Beta anteriores a 3.0.2 en Mac OS X, Windows XP, Windows Vista, y iPhone versiones anteriores a 1.0.1, permite a atacantes remotos omitir el modelo de seguridad de Java y modificar páginas fuera del dominio de seguridad y conducir ataques de tipo cross-site scripting (XSS) por medio de vectores relacionados con la actualización de páginas y redireccionamientos de HTTP.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-04-30 CVE Reserved
- 2007-06-25 CVE Published
- 2024-08-07 CVE Updated
- 2025-01-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://osvdb.org/36452 | Vdb Entry | |
http://www.kb.cert.org/vuls/id/289988 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/Security-announce/2007/Jun/msg00004.html | 2022-08-09 | |
http://www.securityfocus.com/bid/24599 | 2022-08-09 | |
http://www.securitytracker.com/id?1018282 | 2022-08-09 |
URL | Date | SRC |
---|---|---|
http://docs.info.apple.com/article.html?artnum=306173 | 2022-08-09 | |
http://secunia.com/advisories/26287 | 2022-08-09 | |
http://www.vupen.com/english/advisories/2007/2316 | 2022-08-09 | |
http://www.vupen.com/english/advisories/2007/2731 | 2022-08-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |