CVE-2007-2843: Critical severity Safari vulnerability
Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demonstrated by a js script that accesses the location information of cross-domain web pages, probably involving setTimeout and timed events.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2843?
CVE-2007-2843 is considered a moderate severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2007-2843?
The best mitigation for CVE-2007-2843 is to upgrade to a later version of Apple Safari that addresses this vulnerability.
What software is affected by CVE-2007-2843?
CVE-2007-2843 specifically affects Apple Safari version 2.0.4.
What type of vulnerability is CVE-2007-2843?
CVE-2007-2843 is a cross-domain vulnerability that allows unauthorized access to restricted information through JavaScript.
What kind of attack can be executed using CVE-2007-2843?
An attacker could exploit CVE-2007-2843 to execute a script that retrieves the location information from cross-domain web pages.