AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2007-0478

MEDIUM · CVSS 4.3 EPSS 1.62%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-01-25 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2007-0478
Severity
MEDIUM
CVSS
4.3
EPSS
1.62%

Original Filing — NVD Description

WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within an HTML comment.