CVE-2007-3757
- EPSS 1.1%
- Veröffentlicht 27.09.2007 21:17:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Safari in Apple iPhone 1.1.1 allows remote user-assisted attackers to trick the iPhone user into making calls to arbitrary telephone numbers via a crafted "tel:" link that causes iPhone to display a different number than the number that will be diale...
- EPSS 4.93%
- Veröffentlicht 11.09.2007 18:17:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact by setting document.location.hash to a long string. ...
CVE-2007-4431
- EPSS 0.45%
- Veröffentlicht 20.08.2007 19:17:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from local zones to external domains, via a certain body.innerHTML property value, aka "classic JavaScript ...
CVE-2007-4424
- EPSS 0.41%
- Veröffentlicht 18.08.2007 22:17:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Apple Safari for Windows 3.0.3 and earlier does not prompt the user before downloading a file, which allows remote attackers to download arbitrary files to the desktop of a client system via certain HTML, as demonstrated by a filename in the DATA att...
CVE-2007-2408
- EPSS 1.08%
- Veröffentlicht 03.08.2007 20:17:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable Java" setting, which allows remote attackers to execute Java applets via a crafted web page.
CVE-2007-3742
- EPSS 0.62%
- Veröffentlicht 03.08.2007 20:17:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows remote attackers to create a URL containing "look-ali...
CVE-2007-3743
- EPSS 2.66%
- Veröffentlicht 03.08.2007 20:17:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Stack-based buffer overflow in bookmark handling in Apple Safari 3 Beta before Update 3.0.3 on Windows allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a bookmark with a long title.
CVE-2007-3944
- EPSS 17.87%
- Veröffentlicht 23.07.2007 16:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions (PCRE) library in the JavaScript engine in WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, allow remote attackers to execute arbitrary code vi...
CVE-2007-3718
- EPSS 0.59%
- Veröffentlicht 12.07.2007 16:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple unspecified vulnerabilities in the SVG parsing engine in Apple Safari 3 Beta for Windows have unspecified remote attack vectors and impact. NOTE: this issue contains no actionable information, but it was released by a reliable researcher.
CVE-2007-3514
- EPSS 0.2%
- Veröffentlicht 03.07.2007 10:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Cross-domain vulnerability in Apple Safari for Windows 3.0.2 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the do...