CVE-2007-2409: Medium severity Apple iOS and macOS vulnerability
Published Aug 3, 2007
·Updated
Cross-domain vulnerability in WebCore on Apple Mac OS X 10.3.9 and 10.4.10 allows remote attackers to obtain sensitive information via a popup window, which is able to read the current URL of the parent window.
Affected Software
5 affected components
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.4.10
Apple Mac OS X Server=10.3.9
Apple Mac OS X Server=10.4.10
Apple WebCore
Remediation
Patch Available
Patch Available
Patch Available
Event History
Aug 3, 2007
CVE Published
10:17 AM
Data Sourced
10:17 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2409?
CVE-2007-2409 is classified as a moderate vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2007-2409?
To fix CVE-2007-2409, update your Apple Mac OS X or Apple WebCore to the latest version that addresses this vulnerability.
3
Which versions of Apple Mac OS X are affected by CVE-2007-2409?
CVE-2007-2409 affects Apple Mac OS X versions 10.3.9 and 10.4.10.
4
Can CVE-2007-2409 be exploited remotely?
Yes, CVE-2007-2409 can be exploited remotely, allowing attackers to obtain sensitive information through a popup window.
5
Is Apple WebCore related to CVE-2007-2409?
Yes, Apple WebCore is directly related to CVE-2007-2409 as it is the component that contains the vulnerability.