Vulnerability Description
Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords) via the document.loginform.password.value JavaScript parameter loaded from an AppleScript script.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Safari | All versions |
References
- http://securityreason.com/securityalert/2685
- http://www.osvdb.org/35569
- http://www.securityfocus.com/archive/1/467676/100/0/threaded
- http://www.securityfocus.com/archive/1/468544/100/0/threaded
- http://www.securityfocus.com/archive/1/468585/100/0/threaded
- http://www.securityfocus.com/archive/1/468639/100/0/threaded
- http://www.securityfocus.com/archive/1/468650/100/0/threaded
- http://www.securityfocus.com/archive/1/468719/100/0/threaded
- http://www.securityfocus.com/archive/1/468727/100/0/threaded
- http://www.securityfocus.com/archive/1/468737/100/0/threaded
- http://www.securityfocus.com/archive/1/468869/100/0/threaded
- http://www.securityfocus.com/bid/23825
- http://securityreason.com/securityalert/2685
- http://www.osvdb.org/35569
- http://www.securityfocus.com/archive/1/467676/100/0/threaded
FAQ
What is CVE-2007-2580?
CVE-2007-2580 is a vulnerability with a CVSS score of 1.9 (LOW). Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords) via the document.loginform.password.value JavaScript parameter loaded from an Ap...
How severe is CVE-2007-2580?
CVE-2007-2580 has been rated LOW with a CVSS base score of 1.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2580?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Safari.