CVE-2008-1010
published 2008-03-19CVE-2008-1010: Buffer overflow in WebKit, as used in Apple Safari before 3.1, allows remote attackers to execute arbitrary code via crafted regular expressions in JavaScript.
PriorityP334medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.61%
90.7th percentile
Buffer overflow in WebKit, as used in Apple Safari before 3.1, allows remote attackers to execute arbitrary code via crafted regular expressions in JavaScript.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jx7p-gvmq-7763: Buffer overflow in WebKit, as used in Apple Safari before 3
ghsa_unreviewed·2022-05-01
CVE-2008-1010 [MEDIUM] CWE-119 GHSA-jx7p-gvmq-7763: Buffer overflow in WebKit, as used in Apple Safari before 3
Buffer overflow in WebKit, as used in Apple Safari before 3.1, allows remote attackers to execute arbitrary code via crafted regular expressions in JavaScript.
Red Hat
WebKit Arbitrary code execution
vendor_redhat·CVSS 6.8
CVE-2008-1010 [MEDIUM] WebKit Arbitrary code execution
WebKit Arbitrary code execution
Buffer overflow in WebKit, as used in Apple Safari before 3.1, allows remote attackers to execute arbitrary code via crafted regular expressions in JavaScript.
No detection rules found.
Exploit-DB
VideoLAN VLC Media Player 0.9.2 Media Player - XSPF Memory Corruption
exploitdb·2008-10-14
CVE-2008-4558 VideoLAN VLC Media Player 0.9.2 Media Player - XSPF Memory Corruption
VideoLAN VLC Media Player 0.9.2 Media Player - XSPF Memory Corruption
---
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Core Security Technologies - CoreLabs Advisory
http://www.coresecurity.com/corelabs/
VLC media player XSPF Memory Corruption
1. *Advisory Information*
Title: VLC media player XSPF Memory Corruption
Advisory ID: CORE-2008-1010
Advisory URL: http://www.coresecurity.com/content/vlc-xspf-memory-corruption
Date published: 2008-10-14
Date of last update: 2008-10-14
Vendors contacted: VLC
Release mode: Coordinated release
2. *Vulnerability Information*
Class: Memory corruption
Remotely Exploitable: Yes (client side)
Locally Exploitable: No
Bugtraq ID: N/A
CVE Name: N/A
3. *Vulnerability Description*
VLC media player is an open-source, highly portable multimedia play
Exploit-DB
Crysis 1.1.1.5879 - Remote Format String Denial of Service (PoC)
exploitdb·2008-02-28
CVE-2008-1127 Crysis 1.1.1.5879 - Remote Format String Denial of Service (PoC)
Crysis 1.1.1.5879 - Remote Format String Denial of Service (PoC)
---
The Crysis engine passes along internal debug strings through the game. One of them is passed to vsprintf() in the crt lib:
30503263 8D8C24 10100000 LEA ECX,DWORD PTR SS:[ESP+1010]
3050326A 51 PUSH ECX
3050326B 50 PUSH EAX
3050326C 8D5424 08 LEA EDX,DWORD PTR SS:[ESP+8]
30503270 52 PUSH EDX
30503271 FF15 F8A17530 CALL DWORD PTR DS:[] ; MSVCR80.vsprintf
0032CAD8 30503277 w2P0 /CALL to vsprintf from cryactio.30503271
0032CADC 0032CAE8 èÊ2. |buffer = 0032CAE8
0032CAE0 0032DAF8 øÚ2. |format = "Pathfinding in animation graph failed (LONGPOKE%SAAAAAAAA) - no path from 'Parachute_Float_NW' to 'X_Combat_IdleAimingNull_NW'" ; Your name is passed in as part of the format. This is a nono...
0032CAE4 0032DAF8 øÚ2. \arglist
http://docs.info.apple.com/article.html?artnum=307563http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.htmlhttp://secunia.com/advisories/29393http://secunia.com/advisories/29924http://www.securityfocus.com/bid/28290http://www.securityfocus.com/bid/28338http://www.securitytracker.com/id?1019654http://www.us-cert.gov/cas/techalerts/TA08-079A.htmlhttp://www.vupen.com/english/advisories/2008/0920/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41321https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00402.htmlhttp://docs.info.apple.com/article.html?artnum=307563http://lists.apple.com/archives/security-announce/2008/Mar/msg00000.htmlhttp://secunia.com/advisories/29393http://secunia.com/advisories/29924http://www.securityfocus.com/bid/28290http://www.securityfocus.com/bid/28338http://www.securitytracker.com/id?1019654http://www.us-cert.gov/cas/techalerts/TA08-079A.htmlhttp://www.vupen.com/english/advisories/2008/0920/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/41321https://www.redhat.com/archives/fedora-package-announce/2008-April/msg00402.html
2008-03-19
Published