VulnerabilityModified
CVE-2008-1007
WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
MEDIUM 4.3EPSS 2.80%
Does this matter?
Lower severity and a low EPSS score (2.80%). Track it; it rarely justifies an emergency change on its own.
Description
WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.80% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apple/safari
- Source
- cve@mitre.org
References
- http://docs.info.apple.com/article.html?artnum=307563Vendor Advisory
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html
- http://secunia.com/advisories/29393Vendor Advisory
- http://www.securityfocus.com/bid/28290
- http://www.securityfocus.com/bid/28335
- http://www.securitytracker.com/id?1019653
- http://www.us-cert.gov/cas/techalerts/TA08-079A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/0920/referencesVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41324
- http://docs.info.apple.com/article.html?artnum=307563Vendor Advisory
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.html
- http://secunia.com/advisories/29393Vendor Advisory
- http://www.securityfocus.com/bid/28290
- http://www.securityfocus.com/bid/28335
- http://www.securitytracker.com/id?1019653
- http://www.us-cert.gov/cas/techalerts/TA08-079A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/0920/referencesVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41324
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.