First published: Fri Aug 03 2007(Updated: )
WebCore on Apple Mac OS X 10.3.9 and 10.4.10 retains properties of certain global objects when a new URL is visited in the same window, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.3.9 | |
Apple iOS and macOS | =10.4.10 | |
Apple macOS Server | =10.3.9 | |
Apple macOS Server | =10.4.10 | |
Apple WebCore |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2410 is considered a moderate severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2007-2410, update to the latest version of macOS or WebCore that addresses this vulnerability.
CVE-2007-2410 affects Apple Mac OS X versions 10.3.9 and 10.4.10 as well as Apple Mac OS X Server for those same versions.
CVE-2007-2410 facilitates cross-site scripting (XSS) attacks through the improper handling of global object properties.
If you cannot update to fix CVE-2007-2410, consider implementing additional security measures such as input validation and content security policies.