← Back

CVE-2008-2303

nvd nist
Published: Jul 14, 2008Modified: Apr 23, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an out-of-bounds access, a different vulnerability than CVE-2008-2307.

Affected (1)

Products: Apple: Safari
1 product
Safari
Configuration A
1 vulnerable · 13 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Apple
Iphone
Version 1.02
Apple
Iphone
Version 1.0
Apple
Iphone
Version 1.1.3
Apple
Iphone
Version 1.1.4
Apple
Iphone Os
Version 1.0.1
Apple
Iphone Os
Version 1.0.2
Apple
Iphone Os
Version 1.1.1
Apple
Iphone Os
Version 1.1.2
Apple
Ipod Touch
Version 1.1.1
Apple
Ipod Touch
Version 1.1.2
Apple
Ipod Touch
Version 1.1.3
Apple
Ipod Touch
Version 1.1.4
Apple
Ipod Touch
Version 1.1

Related CWEs

Timeline

No history available yet.