CVE-2007-3482
Status: ModifiedHigh (7.8)—
Cross-domain vulnerability in Apple Safari for Windows 3.0.1 allows remote attackers to bypass the "same origin policy" and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.50%
- Percentile among all scored CVEs: 74
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-79
References
Raw JSON (NVD)
Show
{
"id": "CVE-2007-3482",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-06-28T18:30:00.000",
"references": [
{
"url": "http://osvdb.org/38860",
"source": "cve@mitre.org"
},
{
"url": "http://www.0x000000.com/?i=371",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/24700",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/38860",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.0x000000.com/?i=371",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/24700",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-domain vulnerability in Apple Safari for Windows 3.0.1 allows remote attackers to bypass the \"same origin policy\" and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute."
},
{
"lang": "es",
"value": "Una vulnerabilidad de tipo cross-domain en Apple Safari para Windows versión 3.0.1, permite a atacantes remotos omitir la \"same origin policy\" y acceder a información restringida de otros dominios por medio de JavaScript que sobrescribe la variable document y establece estáticamente el atributo document.domain."
}
],
"lastModified": "2026-06-16T22:42:08.147",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:3.0.1:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "03D23398-0916-4E7E-9F22-B01569E3ECD6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE370CAA-04B3-434E-BD5B-1D87DE596C10"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}