CVE-2007-2408: Input Validation
Published Aug 3, 2007
·Updated
WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable Java" setting, which allows remote attackers to execute Java applets via a crafted web page.
Affected Software
4 affected components
Safari=3.0.1
Safari=3.0.1
Safari=3.0.2
Safari=3.0.2
Remediation
Patch Available
Patch Available
Event History
Aug 3, 2007
CVE Published
08:17 PM
Aug 4, 2007
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2408?
The severity of CVE-2007-2408 is classified as moderate due to the potential for remote code execution.
2
What versions of Safari are affected by CVE-2007-2408?
CVE-2007-2408 affects Apple Safari versions 3.0.1 and 3.0.2.
3
How do I fix CVE-2007-2408?
To fix CVE-2007-2408, update Safari to version 3.0.3 or later.
4
What type of vulnerability is CVE-2007-2408?
CVE-2007-2408 is a vulnerability related to improper handling of Java applet settings in WebKit.
5
Can CVE-2007-2408 be exploited remotely?
Yes, CVE-2007-2408 can be exploited remotely through a crafted web page.