HIGH
WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type conversion", which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption
Published Jun 25, 2007
9.3
HIGHCVSS 2.0
EPSS 7.29%
Description
WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type conversion", which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption.
Affected products
No data.
AND
OR
- 10.3.9
- 10.4.9
- 10.3.9
- 10.4.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (14)
- http://docs.info.apple.com/article.html?artnum=305759 x_refsource_CONFIRM
- http://docs.info.apple.com/article.html?artnum=306173 x_refsource_CONFIRM
- http://lists.apple.com/archives/Security-announce/2007/Jun/msg00003.html vendor-advisoryx_refsource_APPLE
- http://osvdb.org/36130 vdb-entryx_refsource_OSVDB
- http://osvdb.org/36450 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/25786 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/26287 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.kb.cert.org/vuls/id/389868 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.securityfocus.com/bid/24597 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1018281 vdb-entryx_refsource_SECTRACKPatch
- http://www.vupen.com/english/advisories/2007/2296 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2007/2316 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2007/2731 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35019 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 25, 2007
Updated Aug 7, 2024
Reserved Apr 30, 2007
Link CVE-2007-2399
CISA Vulnrichment
Updated n/a