Vulnerability Name: | CVE-2007-2408 (CCN-35714) | ||||||||
Assigned: | 2007-07-31 | ||||||||
Published: | 2007-07-31 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable Java" setting, which allows remote attackers to execute Java applets via a crafted web page. | ||||||||
CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-2408 Source: CCN Type: Apple Security Update 2007-007 About Security Update 2007-007 Source: CCN Type: Apple Safari 3 Beta Update 3.0.3 About the security content of Safari 3 Beta Update 3.0.3 Source: CONFIRM Type: Patch http://docs.info.apple.com/article.html?artnum=306174 Source: CCN Type: Apple Web site Apple security updates Source: MISC Type: UNKNOWN http://isc.sans.org/diary.html?storyid=3214 Source: CCN Type: SECTRACK ID: 1018494 Mac OS X WebCore Bugs Permit Cross-Domain Scripting Attacks and Java Settings Bypass Source: CCN Type: Apple Safari Web site Apple - Safari 3 Public Beta Source: CCN Type: OSVDB ID: 36970 Apple Safari WebKit Crafted Web Page Arbitrary Java Applet Execution Source: BID Type: Patch 25157 Source: CCN Type: BID-25157 Apple Safari Disable Java Preference Failure Weakness Source: VUPEN Type: UNKNOWN ADV-2007-2730 Source: XF Type: UNKNOWN safari-applet-security-bypass(35714) Source: XF Type: UNKNOWN safari-applet-security-bypass(35714) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |