← Back

CVE-2007-4692

nvd nist
Published: Nov 15, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated with the active tab.

Affected (3)

Products: Apple: Safari
1 product
Safari
Configuration A
3 vulnerable · 23 platform
Vulnerable SoftwareAffected Versions
Apple
Up to 3.0.3
Version 3.0.2
Version 3.0
Running on/withPlatform Versions
Apple
Mac Os X
Version 10.4.10
Apple
Mac Os X
Version 10.4.1
Apple
Mac Os X
Version 10.4.2
Apple
Mac Os X
Version 10.4.3
Apple
Mac Os X
Version 10.4.4
Apple
Mac Os X
Version 10.4.5
Apple
Mac Os X
Version 10.4.6
Apple
Mac Os X
Version 10.4.7
Apple
Mac Os X
Version 10.4.8
Apple
Mac Os X
Version 10.4.9
Apple
Mac Os X
Version 10.4
Apple
Mac Os X Server
Version 10.4.10
Apple
Mac Os X Server
Version 10.4.1
Apple
Mac Os X Server
Version 10.4.2
Apple
Mac Os X Server
Version 10.4.3
Apple
Mac Os X Server
Version 10.4.4
Apple
Mac Os X Server
Version 10.4.5
Apple
Mac Os X Server
Version 10.4.6
Apple
Mac Os X Server
Version 10.4.7
Apple
Mac Os X Server
Version 10.4.8
Apple
Mac Os X Server
Version 10.4.9
Apple
Mac Os X Server
Version 10.4
Microsoft
Windows
All versions

References (20)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.