CVE-2007-4696: Race Condition
Published Nov 15, 2007
·Updated
Race condition in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain information for forms from other sites via unknown vectors related to "page transitions" in Safari.
Affected Software
20 affected components
Apple iOS and macOS=10.4.3
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.4.10
Apple Mac OS X Server=10.4.9
Apple iOS and macOS=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.4.4
Apple iOS and macOS=10.4.10
Apple Mac OS X Server=10.4.1
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.4
Apple Mac OS X Server=10.4.5
Apple Mac OS X Server=10.4.6
Apple Mac OS X Server=10.4.8
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.4.8
Apple Mac OS X Server=10.4.7
Apple iOS and macOS=10.4.2
Remediation
Event History
Nov 15, 2007
CVE Published
01:46 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4696?
CVE-2007-4696 has been classified with a high severity due to its potential for information disclosure.
2
How do I fix CVE-2007-4696?
To mitigate CVE-2007-4696, it is recommended to update Safari and Mac OS X to the latest versions released by Apple.
3
What types of attacks does CVE-2007-4696 facilitate?
CVE-2007-4696 allows remote attackers to exploit a race condition to obtain sensitive information from forms on other sites.
4
Which versions of macOS are affected by CVE-2007-4696?
CVE-2007-4696 affects Apple Mac OS X versions 10.4 through 10.4.10.
5
Is CVE-2007-4696 specifically targeted at Safari?
Yes, CVE-2007-4696 specifically impacts the WebCore subsystem in Safari on affected versions of Mac OS X.