CVE-2008-3623
published 2008-11-17CVE-2008-3623: Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1 through…
PriorityP343critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
8.37%
94.3th percentile
Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image, related to improper handling of color spaces.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 3.1.2 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce//2008/Nov/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://secunia.com/advisories/32706http://secunia.com/advisories/33179http://support.apple.com/kb/HT3298http://support.apple.com/kb/HT3338http://support.apple.com/kb/HT3639http://www.securityfocus.com/bid/32291http://www.securitytracker.com/id?1021225http://www.us-cert.gov/cas/techalerts/TA08-350A.htmlhttp://www.vupen.com/english/advisories/2008/3444http://www.vupen.com/english/advisories/2009/1621http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce//2008/Nov/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2009/Jun/msg00005.htmlhttp://secunia.com/advisories/32706http://secunia.com/advisories/33179http://support.apple.com/kb/HT3298http://support.apple.com/kb/HT3338http://support.apple.com/kb/HT3639http://www.securityfocus.com/bid/32291http://www.securitytracker.com/id?1021225http://www.us-cert.gov/cas/techalerts/TA08-350A.htmlhttp://www.vupen.com/english/advisories/2008/3444http://www.vupen.com/english/advisories/2009/1621
2008-11-17
Published