CVE-2008-1007: XSS
Published Mar 19, 2008
·Updated
WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
Affected Software
16 affected components
Safari<=3.0.4
Safari=1.3.2
Safari=2.0.2
Safari=3.0.1
Safari=3.0.2
Safari=1.0
Safari=1.3
Safari=3.0.3
Safari=2.0
Safari=0.8
Safari=2.0.4
Safari=1.1
Safari=1.3.1
Safari=1.2
Safari=3.0
Safari=0.9
Event History
Mar 19, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1007?
CVE-2008-1007 is considered a moderate vulnerability that allows for cross-site scripting attacks.
2
Which versions of Apple Safari are affected by CVE-2008-1007?
CVE-2008-1007 affects Apple Safari versions prior to 3.1, including multiple earlier versions.
3
How can I mitigate the risks of CVE-2008-1007?
To mitigate the risks of CVE-2008-1007, users should upgrade to Apple Safari version 3.1 or later.
4
What type of attack does CVE-2008-1007 facilitate?
CVE-2008-1007 facilitates cross-site scripting (XSS) attacks via unprotected Java applets.
5
Is there a workaround for CVE-2008-1007 if I cannot update Safari?
If unable to update Safari due to compatibility issues, avoid using Java applets or limit browser usage for sensitive activities.