CVE-2008-2307
published 2008-06-23CVE-2008-2307: Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 10.4…
PriorityP334critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
7.33%
93.7th percentile
Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 10.4, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors involving JavaScript arrays that trigger memory corruption.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 3.1.1 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4m5c-wmrf-g2j6: Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (applic
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2009-0070 [CRITICAL] GHSA-4m5c-wmrf-g2j6: Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (applic
Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably have unspecified other impact via the array index of the arguments array in a JavaScript function, possibly a related issue to CVE-2008-2307.
GHSA
GHSA-9622-pfwg-vcxc: Integer signedness error in Safari on Apple iPhone before 2
ghsa_unreviewed·2022-05-01·CVSS 9.3
CVE-2008-2303 [CRITICAL] GHSA-9622-pfwg-vcxc: Integer signedness error in Safari on Apple iPhone before 2
Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an out-of-bounds access, a different vulnerability than CVE-2008-2307.
GHSA
GHSA-2whf-mx89-7886: Unspecified vulnerability in WebKit in Apple Safari before 3
ghsa_unreviewed·2022-05-01
CVE-2008-2307 [HIGH] GHSA-2whf-mx89-7886: Unspecified vulnerability in WebKit in Apple Safari before 3
Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 10.4, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors involving JavaScript arrays that trigger memory corruption.
Red Hat
WebKit: memory corruption in handling of JavaScript arrays
vendor_redhat·2008-06-19·CVSS 9.3
CVE-2008-2307 [CRITICAL] WebKit: memory corruption in handling of JavaScript arrays
WebKit: memory corruption in handling of JavaScript arrays
Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 10.4, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors involving JavaScript arrays that trigger memory corruption.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2008//Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2008//Jun/msg00003.htmlhttp://secunia.com/advisories/30775http://secunia.com/advisories/30801http://secunia.com/advisories/30992http://secunia.com/advisories/31074http://support.apple.com/kb/HT2092http://support.apple.com/kb/HT2163http://support.apple.com/kb/HT2165http://www.kb.cert.org/vuls/id/361043http://www.securityfocus.com/bid/29836http://www.securitytracker.com/id?1020330http://www.vupen.com/english/advisories/2008/1882/referenceshttp://www.vupen.com/english/advisories/2008/1980http://www.vupen.com/english/advisories/2008/1981/referenceshttp://www.vupen.com/english/advisories/2008/2094/referenceshttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg00279.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg00319.htmlhttp://lists.apple.com/archives/security-announce/2008//Jul/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2008//Jun/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2008//Jun/msg00003.htmlhttp://secunia.com/advisories/30775http://secunia.com/advisories/30801http://secunia.com/advisories/30992http://secunia.com/advisories/31074http://support.apple.com/kb/HT2092http://support.apple.com/kb/HT2163http://support.apple.com/kb/HT2165http://www.kb.cert.org/vuls/id/361043http://www.securityfocus.com/bid/29836http://www.securitytracker.com/id?1020330http://www.vupen.com/english/advisories/2008/1882/referenceshttp://www.vupen.com/english/advisories/2008/1980http://www.vupen.com/english/advisories/2008/1981/referenceshttp://www.vupen.com/english/advisories/2008/2094/referenceshttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg00279.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg00319.html
2008-06-23
Published