Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3950

Опубликовано: 16 сент. 2008
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod touch 1.1.4 and 2.0 allows remote attackers to cause a denial of service (browser crash) via a JavaScript alert call with an argument that lacks breakable characters and has a length that is a multiple of the memory page size, leading to an out-of-bounds read.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:h:apple:iphone:1.1.4:*:*:*:*:*:*:*
cpe:2.3:h:apple:iphone:2.0:*:*:*:*:*:*:*
cpe:2.3:h:apple:ipod_touch:1.1.4:*:*:*:*:*:*:*
cpe:2.3:h:apple:ipod_touch:2.0:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*

EPSS

Процентиль: 91%
0.06514
Низкий

5 Medium

CVSS2

Дефекты

CWE-189

Связанные уязвимости

ubuntu
больше 17 лет назад

Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod touch 1.1.4 and 2.0 allows remote attackers to cause a denial of service (browser crash) via a JavaScript alert call with an argument that lacks breakable characters and has a length that is a multiple of the memory page size, leading to an out-of-bounds read.

debian
больше 17 лет назад

Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:me ...

github
почти 4 года назад

Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod touch 1.1.4 and 2.0 allows remote attackers to cause a denial of service (browser crash) via a JavaScript alert call with an argument that lacks breakable characters and has a length that is a multiple of the memory page size, leading to an out-of-bounds read.

EPSS

Процентиль: 91%
0.06514
Низкий

5 Medium

CVSS2

Дефекты

CWE-189