ID

VAR-200706-0106


CVE

CVE-2007-3185


TITLE

Apple Safari Service disruption in (DoS) Vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2007-002178

DESCRIPTION

Apple Safari Beta 3.0.1 for Windows public beta allows remote attackers to cause a denial of service (crash) via unspecified DHTML manipulations that trigger memory corruption, as demonstrated using Hamachi. Apple Safari for Windows is prone to multiple remote code-execution and denial-of-service vulnerabilities. An attacker may exploit these issues by enticing victims into opening a maliciously crafted HTML document. Successful exploits can allow attackers to execute arbitrary code in the context of the affected browser or to cause denial-of-service conditions. Safari 3 public beta for Windows is reported vulnerable. One of these issues may be related to BID 24431: Apple Safari for Windows Unspecified Denial of Service Vulnerability. NOTE: Apple has released Safari 3.0.1 Beta for Windows UPDATE (June 14, 2007): Safari 2.0.4 is vulnerable; prior versions may also be affected. Apple Safari is a WEB browser used by the Apple family of operating systems. There is a vulnerability in Apple Safari's handling of malformed webpages, which may be exploited by remote attackers to cause the browser to crash. If the user visits a malicious site using the Safari browser on the Windows platform, it may cause an out-of-bounds memory read and the application may terminate unexpectedly

Trust: 1.98

sources: NVD: CVE-2007-3185 // JVNDB: JVNDB-2007-002178 // BID: 24433 // VULHUB: VHN-26547

AFFECTED PRODUCTS

vendor:applemodel:safariscope:eqversion:3.0.1

Trust: 1.6

vendor:applemodel:safariscope:eqversion:windows edition beta 3.0.1

Trust: 0.8

vendor:applemodel:safariscope:eqversion:2.0.4

Trust: 0.3

vendor:applemodel:safari beta for windowsscope:eqversion:3

Trust: 0.3

vendor:applemodel:safari beta for windowsscope:neversion:3.0.1

Trust: 0.3

sources: BID: 24433 // JVNDB: JVNDB-2007-002178 // CNNVD: CNNVD-200706-183 // NVD: CVE-2007-3185

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-3185
value: HIGH

Trust: 1.0

NVD: CVE-2007-3185
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200706-183
value: HIGH

Trust: 0.6

VULHUB: VHN-26547
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2007-3185
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-26547
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-26547 // JVNDB: JVNDB-2007-002178 // CNNVD: CNNVD-200706-183 // NVD: CVE-2007-3185

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: VULHUB: VHN-26547 // JVNDB: JVNDB-2007-002178 // NVD: CVE-2007-3185

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200706-183

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-200706-183

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-002178

PATCH

title:APPLE-SA-2007-06-14url:http://lists.apple.com/archives/security-announce/2007/Jun/msg00000.html

Trust: 0.8

sources: JVNDB: JVNDB-2007-002178

EXTERNAL IDS

db:NVDid:CVE-2007-3185

Trust: 2.8

db:BIDid:24433

Trust: 2.0

db:VUPENid:ADV-2007-2192

Trust: 1.7

db:OSVDBid:38541

Trust: 1.7

db:JVNDBid:JVNDB-2007-002178

Trust: 0.8

db:CNNVDid:CNNVD-200706-183

Trust: 0.7

db:APPLEid:APPLE-SA-2007-06-14

Trust: 0.6

db:XFid:34846

Trust: 0.6

db:VULHUBid:VHN-26547

Trust: 0.1

sources: VULHUB: VHN-26547 // BID: 24433 // JVNDB: JVNDB-2007-002178 // CNNVD: CNNVD-200706-183 // NVD: CVE-2007-3185

REFERENCES

url:http://lists.apple.com/archives/security-announce/2007/jun/msg00000.html

Trust: 1.7

url:http://www.securityfocus.com/bid/24433

Trust: 1.7

url:http://aviv.raffon.net/2007/06/11/applesafariforwindowsoutwithacrash.aspx

Trust: 1.7

url:http://osvdb.org/38541

Trust: 1.7

url:http://www.vupen.com/english/advisories/2007/2192

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/34846

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-3185

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-3185

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/34846

Trust: 0.6

url:http://www.frsirt.com/english/advisories/2007/2192

Trust: 0.6

url:http://erratasec.blogspot.com/2007/06/niiiice.html

Trust: 0.3

url:http://www.apple.com/safari/

Trust: 0.3

sources: VULHUB: VHN-26547 // BID: 24433 // JVNDB: JVNDB-2007-002178 // CNNVD: CNNVD-200706-183 // NVD: CVE-2007-3185

CREDITS

David Maynor

Trust: 0.6

sources: CNNVD: CNNVD-200706-183

SOURCES

db:VULHUBid:VHN-26547
db:BIDid:24433
db:JVNDBid:JVNDB-2007-002178
db:CNNVDid:CNNVD-200706-183
db:NVDid:CVE-2007-3185

LAST UPDATE DATE

2024-08-14T14:59:00.959000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-26547date:2017-07-29T00:00:00
db:BIDid:24433date:2007-06-15T19:19:00
db:JVNDBid:JVNDB-2007-002178date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200706-183date:2007-06-13T00:00:00
db:NVDid:CVE-2007-3185date:2017-07-29T01:32:02.457

SOURCES RELEASE DATE

db:VULHUBid:VHN-26547date:2007-06-12T00:00:00
db:BIDid:24433date:2007-06-11T00:00:00
db:JVNDBid:JVNDB-2007-002178date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200706-183date:2007-06-12T00:00:00
db:NVDid:CVE-2007-3185date:2007-06-12T22:30:00