CVE-2008-3632
published 2008-09-11CVE-2008-3632: Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code…
PriorityP334critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.95%
92.4th percentile
Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a web page with crafted Cascading Style Sheets (CSS) import statements.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone | — | — |
| apple | iphone | — | — |
| apple | iphone | — | — |
| apple | iphone | — | — |
| apple | iphone | — | — |
| apple | iphone | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | ipod_touch | — | — |
| apple | ipod_touch | — | — |
| apple | ipod_touch | — | — |
| apple | ipod_touch | — | — |
| apple | ipod_touch | — | — |
| apple | ipod_touch | — | — |
| apple | ipod_touch | — | — |
| apple | ipod_touch | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3p8g-7gxj-j8h5: Use-after-free vulnerability in WebKit in Apple iPod touch 1
ghsa_unreviewed·2022-05-02
CVE-2008-3632 [HIGH] GHSA-3p8g-7gxj-j8h5: Use-after-free vulnerability in WebKit in Apple iPod touch 1
Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a web page with crafted Cascading Style Sheets (CSS) import statements.
Ubuntu
WebKit vulnerability
vendor_ubuntu·2008-11-24
CVE-2008-3632 WebKit vulnerability
Title: WebKit vulnerability
Summary: WebKit vulnerability
It was discovered that WebKit did not properly handle Cascading Style Sheets
(CSS) import statements. If a user were tricked into opening a malicious
website, an attacker could cause a browser crash and possibly execute
arbitrary code with user privileges.
Instructions: After a standard system upgrade you need to restart any applications that
use WebKit, such as Epiphany-webkit and Midori, to effect the necessary
changes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce//2008/Sep/msg00003.htmlhttp://lists.apple.com/archives/security-announce//2008/Sep/msg00004.htmlhttp://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.htmlhttp://secunia.com/advisories/31823http://secunia.com/advisories/31900http://secunia.com/advisories/32099http://secunia.com/advisories/32860http://secunia.com/advisories/35379http://support.apple.com/kb/HT3026http://support.apple.com/kb/HT3129http://support.apple.com/kb/HT3613http://www.securityfocus.com/bid/31092http://www.securitytracker.com/id?1020847http://www.ubuntu.com/usn/USN-676-1http://www.vupen.com/english/advisories/2008/2525http://www.vupen.com/english/advisories/2008/2558http://www.vupen.com/english/advisories/2009/1522http://lists.apple.com/archives/security-announce//2008/Sep/msg00003.htmlhttp://lists.apple.com/archives/security-announce//2008/Sep/msg00004.htmlhttp://lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.htmlhttp://secunia.com/advisories/31823http://secunia.com/advisories/31900http://secunia.com/advisories/32099http://secunia.com/advisories/32860http://secunia.com/advisories/35379http://support.apple.com/kb/HT3026http://support.apple.com/kb/HT3129http://support.apple.com/kb/HT3613http://www.securityfocus.com/bid/31092http://www.securitytracker.com/id?1020847http://www.ubuntu.com/usn/USN-676-1http://www.vupen.com/english/advisories/2008/2525http://www.vupen.com/english/advisories/2008/2558http://www.vupen.com/english/advisories/2009/1522
2008-09-11
Published