CVE

Id
31124  
CVE No.
CVE-2008-1007  
Status
Candidate  
Description
WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site scripting (XSS) attacks.  
Phase
Assigned (20080226)  
Votes
None (candidate not yet proposed)  
Comments