CVE-2005-2272

medium

Description

Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/21070

http://www.vupen.com/english/advisories/2005/2659

http://www.securityfocus.com/bid/14011

http://www.osvdb.org/17397

http://securitytracker.com/id?1015294

http://secunia.com/advisories/17813

http://secunia.com/advisories/15474

http://docs.info.apple.com/article.html?artnum=302847

Details

Source: Mitre, NVD

Published: 2005-07-13

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 2.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Severity: Medium