4.3

CVE-2008-1589

Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for visiting a web site with a (1) self-signed or (2) invalid certificate, which makes it easier for remote attackers to spoof web sites.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ Safari
   Apple ≫ Iphone Version 1.0
   Apple ≫ Iphone Version 1.1.3
   Apple ≫ Iphone Version 1.1.4
   Apple ≫ Iphone Version 1.02
   Apple ≫ Ipod Touch Version 1.1
   Apple ≫ Ipod Touch Version 1.1.1
   Apple ≫ Ipod Touch Version 1.1.2
   Apple ≫ Ipod Touch Version 1.1.3
   Apple ≫ Ipod Touch Version 1.1.4
   Apple ≫ iPhone OS Version 1.0.1
   Apple ≫ iPhone OS Version 1.0.2
   Apple ≫ iPhone OS Version 1.1.1
   Apple ≫ iPhone OS Version 1.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.21% 0.646
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html
http://secunia.com/advisories/31074
http://www.vupen.com/english/advisories/2008/2094/references
http://www.securityfocus.com/bid/30186
http://jvn.jp/en/jp/JVN88676089/index.html
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000039.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/43734