The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated with the active tab.
Advisories
Source ID Title
EUVD EUVD EUVD-2007-4674 The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication sheet to be displayed for a tab that is not active, which makes it appear as if it is associated with the active tab.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T15:01:09.948Z

Reserved: 2007-09-05T00:00:00

Link: CVE-2007-4692

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2007-11-15T00:46:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2007-4692

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.