← Back

CVE-2007-5858

nvd nist
Published: Dec 19, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

WebKit in Safari in Apple Mac OS X 10.4.11 and 10.5.1, iPhone 1.0 through 1.1.2, and iPod touch 1.1 through 1.1.2 allows remote attackers to "navigate the subframes of any other page," which can be leveraged to conduct cross-site scripting (XSS) attacks and obtain sensitive information.

Affected (1)

Products: Apple: Safari
1 product
Safari
Configuration A
1 vulnerable · 11 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Apple
Mac Os X
Version 10.4.11
Apple
Mac Os X
Version 10.5.1
Apple
Iphone
Version 1.02
Apple
Iphone
Version 1.0
Apple
Iphone Os
Version 1.0.1
Apple
Iphone Os
Version 1.0.2
Apple
Iphone Os
Version 1.1.1
Apple
Iphone Os
Version 1.1.2
Apple
Ipod Touch
Version 1.1.1
Apple
Ipod Touch
Version 1.1.2
Apple
Ipod Touch
Version 1.1

References (26)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
US Government Resource
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.