9.3

CVE-2008-2317

WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via a reference to the ownerNode property of a copied CSSStyleSheet object of a STYLE element, as originally demonstrated on Apple iPhone before 2.0 and iPod touch before 2.0, a different vulnerability than CVE-2008-1590.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AppleSafari
   AppleIphone Version1.0
   AppleIphone Version1.1
   AppleIphone Version1.1.3
   AppleIpod Touch Version <= 1.1.4
   AppleIpod Touch Version1.1
   AppleIpod Touch Version1.1.1
   AppleIpod Touch Version1.1.2
   AppleIpod Touch Version1.1.3
   AppleiPhone OS Version <= 1.1.4
   AppleiPhone OS Version1.0.1
   AppleiPhone OS Version1.0.2
   AppleiPhone OS Version1.1.1
   AppleiPhone OS Version1.1.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 14.24% 0.937
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C