CVE-2008-2303

Apple Safari - Numeric Error

Title source: rule

Description

Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an out-of-bounds access, a different vulnerability than CVE-2008-2307.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Hiromitsu Takagi · htmlremoteosx
https://www.exploit-db.com/exploits/32048

Scores

EPSS 0.1599
EPSS Percentile 94.8%

Details

CWE
CWE-189
Status published
Products (1)
apple/safari
Published Jul 14, 2008
Tracked Since Feb 18, 2026