// For flags

CVE-2008-3950

Apple iOS 1.1.4/2.0 / iPod 1.1.4/2.0 touch Safari WebKit - 'alert()' Remote Denial of Service

Severity Score

6.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod touch 1.1.4 and 2.0 allows remote attackers to cause a denial of service (browser crash) via a JavaScript alert call with an argument that lacks breakable characters and has a length that is a multiple of the memory page size, leading to an out-of-bounds read.

Error de superación de límite en la función _web_drawInRect:withFont:ellipsis:alignment:measureOnly en el WebKit en Safari en Apple iPhone 1.1.4 y 2.0 e iPod touch 1.1.4 y 2.0, permite a atacantes remotos provocar una denegación de servicio (caída de navegador) a través de una llamada a una alerta JavaScript con un argumento que carece de caracteres frágiles y tiene una longitud que es múltiplo del tamaño de memoria, lo que conduce a una lectura fuera de límites.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-09-05 CVE Reserved
  • 2008-09-12 First Exploit
  • 2008-09-16 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-189: Numeric Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apple
Search vendor "Apple"
Iphone
Search vendor "Apple" for product "Iphone"
1.1.4
Search vendor "Apple" for product "Iphone" and version "1.1.4"
-
Affected
in Apple
Search vendor "Apple"
Safari
Search vendor "Apple" for product "Safari"
*-
Affected
Apple
Search vendor "Apple"
Iphone
Search vendor "Apple" for product "Iphone"
2.0
Search vendor "Apple" for product "Iphone" and version "2.0"
-
Affected
in Apple
Search vendor "Apple"
Safari
Search vendor "Apple" for product "Safari"
*-
Affected
Apple
Search vendor "Apple"
Ipod Touch
Search vendor "Apple" for product "Ipod Touch"
1.1.4
Search vendor "Apple" for product "Ipod Touch" and version "1.1.4"
-
Affected
in Apple
Search vendor "Apple"
Safari
Search vendor "Apple" for product "Safari"
*-
Affected
Apple
Search vendor "Apple"
Ipod Touch
Search vendor "Apple" for product "Ipod Touch"
2.0
Search vendor "Apple" for product "Ipod Touch" and version "2.0"
-
Affected
in Apple
Search vendor "Apple"
Safari
Search vendor "Apple" for product "Safari"
*-
Affected