CVE-2007-5858

WebKit in Safari in Apple Mac OS X 10.4.11 and 10.5.1, iPhone 1.0 through 1.1.2, and iPod touch 1.1 through 1.1.2 allows remote attackers to "navigate the subframes of any other page," which can be leveraged to conduct cross-site scripting (XSS) attacks and obtain sensitive information.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*
OR cpe:2.3:h:apple:iphone:1.0:*:*:*:*:*:*:*
cpe:2.3:h:apple:iphone:1.02:*:*:*:*:*:*:*
cpe:2.3:h:apple:ipod_touch:1.1:*:*:*:*:*:*:*
cpe:2.3:h:apple:ipod_touch:1.1.1:*:*:*:*:*:*:*
cpe:2.3:h:apple:ipod_touch:1.1.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*

History

09 Aug 2022, 13:46

Type Values Removed Values Added
First Time Apple iphone Os
CPE cpe:2.3:h:apple:iphone:1.1.1:*:*:*:*:*:*:*
cpe:2.3:h:apple:iphone:1.0.1:*:*:*:*:*:*:*
cpe:2.3:h:apple:iphone:1.0.2:*:*:*:*:*:*:*
cpe:2.3:h:apple:iphone:1.1.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*

Information

Published : 2007-12-19 21:46

Updated : 2023-12-10 10:40


NVD link : CVE-2007-5858

Mitre link : CVE-2007-5858

CVE.ORG link : CVE-2007-5858


JSON object : View

Products Affected

apple

  • iphone_os
  • safari
  • mac_os_x
  • iphone
  • ipod_touch
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')