Cross-Site Scripting Vulnerability in Apple Safari on Mac OS X
CVE-2007-2410
Currently unrated
What is CVE-2007-2410?
In certain versions of Apple Safari running on Mac OS X 10.3.9 and 10.4.10, the WebCore component fails to properly clear certain global object properties when a new URL is accessed in the same browser window. This oversight allows remote attackers to exploit the vulnerability to execute arbitrary JavaScript code via specially crafted web pages. Successful exploitation could lead to unauthorized actions taken on behalf of users or the exposure of sensitive information.