9.3

CVE-2008-2306

Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows remote attackers to bypass intended access restrictions, and force a client system to download and execute arbitrary files.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AppleSafari Version <= 3.1.1
AppleSafari Version3.0
AppleSafari Version3.0.1
AppleSafari Version3.0.2
AppleSafari Version3.0.3
AppleSafari Version3.0.4
AppleSafari Version3.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.634
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C