← All CVEs

CVE-2008-2303

high · 10

Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an out-of-bounds access, a different vulnerability than CVE-2008-2307.

10
CVSS
13.0%
EPSS (exploit prob.)
96th
EPSS percentile
2008-07-14
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
appleiphone1.0
appleiphone1.1.3
appleiphone1.1.4
appleiphone1.02
appleipod_touch1.1
appleipod_touch1.1.1
appleipod_touch1.1.2
appleipod_touch1.1.3
appleipod_touch1.1.4
appleiphone_os1.0.1
appleiphone_os1.0.2
appleiphone_os1.1.1
appleiphone_os1.1.2
applesafariall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-2303