CVE Vulnerabilities

CVE-2008-2303

Published: Jul 14, 2008 | Modified: Aug 09, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an out-of-bounds access, a different vulnerability than CVE-2008-2307.

Affected Software

Name Vendor Start Version End Version
Iphone Apple 1.0 (including) 1.0 (including)
Iphone Apple 1.1.3 (including) 1.1.3 (including)
Iphone Apple 1.1.4 (including) 1.1.4 (including)
Iphone Apple 1.02 (including) 1.02 (including)
Ipod_touch Apple 1.1 (including) 1.1 (including)
Ipod_touch Apple 1.1.1 (including) 1.1.1 (including)
Ipod_touch Apple 1.1.2 (including) 1.1.2 (including)
Ipod_touch Apple 1.1.3 (including) 1.1.3 (including)
Ipod_touch Apple 1.1.4 (including) 1.1.4 (including)
Iphone_os Apple 1.0.1 (including) 1.0.1 (including)
Iphone_os Apple 1.0.2 (including) 1.0.2 (including)
Iphone_os Apple 1.1.1 (including) 1.1.1 (including)
Iphone_os Apple 1.1.2 (including) 1.1.2 (including)

References