CVE-2007-4671
- EPSS 2.96%
- Veröffentlicht 27.09.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to "alter or access" HTTPS content via an HTTP session with a crafted web page that...
CVE-2007-3756
- EPSS 1.09%
- Veröffentlicht 27.09.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of the parent window, even when t...
CVE-2007-3757
- EPSS 1.06%
- Veröffentlicht 27.09.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Safari in Apple iPhone 1.1.1 allows remote user-assisted attackers to trick the iPhone user into making calls to arbitrary telephone numbers via a crafted "tel:" link that causes iPhone to display a different number than the number that will be diale...
- EPSS 4.1%
- Veröffentlicht 11.09.2007 18:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact by setting document.location.hash to a long string. ...
CVE-2007-4431
- EPSS 0.37%
- Veröffentlicht 20.08.2007 19:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from local zones to external domains, via a certain body.innerHTML property value, aka "classic JavaScript ...
CVE-2007-4424
- EPSS 0.35%
- Veröffentlicht 18.08.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apple Safari for Windows 3.0.3 and earlier does not prompt the user before downloading a file, which allows remote attackers to download arbitrary files to the desktop of a client system via certain HTML, as demonstrated by a filename in the DATA att...
CVE-2007-2408
- EPSS 0.76%
- Veröffentlicht 03.08.2007 20:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable Java" setting, which allows remote attackers to execute Java applets via a crafted web page.
CVE-2007-3742
- EPSS 0.61%
- Veröffentlicht 03.08.2007 20:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows remote attackers to create a URL containing "look-ali...
CVE-2007-3743
- EPSS 1.95%
- Veröffentlicht 03.08.2007 20:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in bookmark handling in Apple Safari 3 Beta before Update 3.0.3 on Windows allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a bookmark with a long title.
CVE-2007-3944
- EPSS 36.79%
- Veröffentlicht 23.07.2007 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions (PCRE) library in the JavaScript engine in WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, allow remote attackers to execute arbitrary code vi...