CVE-2007-2400

Apple Safari <3.0.2 - XSS

Title source: llm

Description

Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects.

Scores

EPSS 0.0046
EPSS Percentile 63.6%

Classification

CWE
CWE-362 CWE-79
Status draft

Affected Products (3)

apple/iphone_os < 1.0
apple/safari
apple/safari

Timeline

Published Jun 25, 2007
Tracked Since Feb 18, 2026