CVE-2007-2400

Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*
OR cpe:2.3:a:apple:safari:3.0:*:windows:*:*:*:*:*
cpe:2.3:a:apple:safari:3.0.1:*:windows:*:*:*:*:*

History

21 Nov 2024, 00:30

Type Values Removed Values Added
References () http://docs.info.apple.com/article.html?artnum=306173 - Vendor Advisory () http://docs.info.apple.com/article.html?artnum=306173 - Vendor Advisory
References () http://lists.apple.com/archives/Security-announce/2007/Jun/msg00004.html - Patch, Vendor Advisory () http://lists.apple.com/archives/Security-announce/2007/Jun/msg00004.html - Patch, Vendor Advisory
References () http://osvdb.org/36452 - () http://osvdb.org/36452 -
References () http://secunia.com/advisories/26287 - Vendor Advisory () http://secunia.com/advisories/26287 - Vendor Advisory
References () http://www.kb.cert.org/vuls/id/289988 - US Government Resource () http://www.kb.cert.org/vuls/id/289988 - US Government Resource
References () http://www.securityfocus.com/bid/24599 - Patch () http://www.securityfocus.com/bid/24599 - Patch
References () http://www.securitytracker.com/id?1018282 - Patch () http://www.securitytracker.com/id?1018282 - Patch
References () http://www.vupen.com/english/advisories/2007/2316 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/2316 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2007/2731 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/2731 - Vendor Advisory

Information

Published : 2007-06-25 19:30

Updated : 2024-11-21 00:30


NVD link : CVE-2007-2400

Mitre link : CVE-2007-2400

CVE.ORG link : CVE-2007-2400


JSON object : View

Products Affected

apple

  • mac_os_x
  • iphone_os
  • safari

microsoft

  • windows_vista
  • windows_xp
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')