CVE-2008-2307
Apple Safari < 3.1.2 - Remote Code Execution via JavaScript Array Memory Corruption
Title source: llmDescription
Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 10.4, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors involving JavaScript arrays that trigger memory corruption.
References (19)
Core 19
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT2163
Vendor Advisory vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00319.html
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1981/references
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT2165
Vendor Advisory vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg00279.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/30775
Mailing List vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2008//Jun/msg00003.html
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/30801
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1882/references
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT2092
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/30992
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2008//Jul/msg00001.html
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/361043
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/29836
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2094/references
Patch, Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2008//Jun/msg00001.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1020330
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/31074
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1980
Scores
EPSS
0.0733
EPSS Percentile
93.7%
Details
CWE
CWE-399
Status
published
Products (7)
apple/safari
3.0
apple/safari
3.0.1
apple/safari
3.0.2
apple/safari
3.0.3
apple/safari
3.0.4
apple/safari
3.1
apple/safari
< 3.1.1
Published
Jun 23, 2008
Tracked Since
Feb 18, 2026