Vulnerability Name: | CVE-2007-3759 (CCN-36858) | ||||||||
Assigned: | 2007-09-27 | ||||||||
Published: | 2007-09-27 | ||||||||
Updated: | 2022-08-09 | ||||||||
Summary: | Safari in Apple iPhone 1.1.1, when requested to disable Javascript, does not disable it until Safari is restarted, which might leave Safari open to attacks that the user does not expect. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-16 | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-3759 Source: CCN Type: Apple Web site About the security content of the iPhone 1.1.1 Update Source: CONFIRM Type: UNKNOWN http://docs.info.apple.com/article.html?artnum=306586 Source: APPLE Type: Patch APPLE-SA-2007-09-27 Source: OSVDB Type: UNKNOWN 38532 Source: CCN Type: SA26983 Apple iPhone Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 26983 Source: CCN Type: SECTRACK ID: 1018752 Apple iPhone Bugs Let Remote Users Dial Phone Numbers, Execute Arbitrary Code, and Conduct Cross-Site Scripting Attacks Source: SECTRACK Type: UNKNOWN 1018752 Source: CCN Type: OSVDB ID: 38532 Apple Safari on iPhone JavaScript Functionality Persistence Source: BID Type: UNKNOWN 25853 Source: CCN Type: BID-25853 Apple iPhone Mobile Safari Browser JavaScript Execution Weakness Source: XF Type: UNKNOWN iphone-javascript-weak-security(36858) Source: XF Type: UNKNOWN iphone-javascript-weak-security(36858) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |