CVE Vulnerabilities

CVE-2008-2303

Published: Jul 14, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an out-of-bounds access, a different vulnerability than CVE-2008-2307.

Affected Software

NameVendorStart VersionEnd Version
IphoneApple1.0 (including)1.0 (including)
IphoneApple1.1.3 (including)1.1.3 (including)
IphoneApple1.1.4 (including)1.1.4 (including)
IphoneApple1.02 (including)1.02 (including)
Ipod_touchApple1.1 (including)1.1 (including)
Ipod_touchApple1.1.1 (including)1.1.1 (including)
Ipod_touchApple1.1.2 (including)1.1.2 (including)
Ipod_touchApple1.1.3 (including)1.1.3 (including)
Ipod_touchApple1.1.4 (including)1.1.4 (including)
Iphone_osApple1.0.1 (including)1.0.1 (including)
Iphone_osApple1.0.2 (including)1.0.2 (including)
Iphone_osApple1.1.1 (including)1.1.1 (including)
Iphone_osApple1.1.2 (including)1.1.2 (including)

References