Vulnerability Details CVE-2006-1987
Apple Safari 2.0.3 allows remote attackers to cause a denial of service and possibly execute code via an invalid FRAME tag, possibly due to (1) multiple SCROLLING attributes with no values, or (2) a SRC attribute with no value. NOTE: due to lack of diagnosis by the researcher, it is unclear which vector is responsible.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.045
EPSS Ranking 88.7%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2006-1987
-
cpe:2.3:a:apple:safari:2.0
-
cpe:2.3:a:apple:safari:2.0.1
-
cpe:2.3:a:apple:safari:2.0.2
-
cpe:2.3:a:apple:safari:2.0.3