CVE-2007-0478
Apple Safari - XSS
Title source: ruleDescription
WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within an HTML comment.
References (11)
Scores
EPSS
0.0376
EPSS Percentile
87.9%
Classification
CWE
CWE-79
Status
draft
Affected Products (2)
apple/safari
apple/webcore
Timeline
Published
Jan 25, 2007
Tracked Since
Feb 18, 2026