CVE-2008-1036

Apple Mac OS X - XSS

Title source: rule

Description

The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character encodings, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.

Scores

EPSS 0.0264
EPSS Percentile 85.5%

Classification

CWE
CWE-79
Status draft

Affected Products (9)

apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x
apple/mac_os_x_server
apple/mac_os_x_server
apple/mac_os_x_server
apple/mac_os_x_server
redhat/enterprise_linux

Timeline

Published Jun 02, 2008
Tracked Since Feb 18, 2026