Description
Cross-domain vulnerability in Apple Safari for Windows 3.0.2 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute to a file:// location, a different vector than CVE-2007-3482.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2007-3498 | Cross-domain vulnerability in Apple Safari for Windows 3.0.2 allows remote attackers to bypass the Same Origin Policy and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute to a file:// location, a different vector than CVE-2007-3482. |
References
| Link | Providers |
|---|---|
| http://osvdb.org/38861 |
|
| http://www.0x000000.com/?i=371 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T14:21:36.307Z
Reserved: 2007-07-02T00:00:00.000Z
Link: CVE-2007-3514
No data.
Status : Modified
Published: 2007-07-03T10:30:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2007-3514
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD