6.8

CVE-2008-1590

JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger memory corruption, a different vulnerability than CVE-2008-2317.

Data is provided by the National Vulnerability Database (NVD)
WebkitJavascriptcore
   AppleIphone Version1.0
   AppleIphone Version1.1.3
   AppleIphone Version1.1.4
   AppleIphone Version1.02
   AppleIpod Touch Version1.1
   AppleIpod Touch Version1.1.1
   AppleIpod Touch Version1.1.2
   AppleIpod Touch Version1.1.3
   AppleIpod Touch Version1.1.4
   AppleiPhone OS Version1.0.1
   AppleiPhone OS Version1.0.2
   AppleiPhone OS Version1.1.1
   AppleiPhone OS Version1.1.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.88% 0.815
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P