← Back

CVE-2008-2317

nvd nist
Published: Jul 14, 2008Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via a reference to the ownerNode property of a copied CSSStyleSheet object of a STYLE element, as originally demonstrated on Apple iPhone before 2.0 and iPod touch before 2.0, a different vulnerability than CVE-2008-1590.

Affected (1)

Products: Apple: Safari
1 product
Safari
Configuration A
1 vulnerable · 13 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Apple
Iphone
Version 1.0
Apple
Iphone
Version 1.1.3
Apple
Iphone
Version 1.1
Apple
Iphone Os
Up to 1.1.4
Apple
Iphone Os
Version 1.0.1
Apple
Iphone Os
Version 1.0.2
Apple
Iphone Os
Version 1.1.1
Apple
Iphone Os
Version 1.1.2
Apple
Ipod Touch
Up to 1.1.4
Apple
Ipod Touch
Version 1.1.1
Apple
Ipod Touch
Version 1.1.2
Apple
Ipod Touch
Version 1.1.3
Apple
Ipod Touch
Version 1.1

Related CWEs

References (20)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.