CVE-2008-2321

CoreGraphics - Remote Code Execution or Denial of Service via Argument Processing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-2321. PoCs published by Michal Zalewski.

AI-analyzed exploit summary This is a fuzzer for CVE-2008-2321, targeting memory corruption vulnerabilities in the CoreGraphics component of Mac OS X. It tests various canvas operations to trigger potential exploits or denial-of-service conditions.

Description

Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unknown vectors involving "processing of arguments."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Michal Zalewski · htmldososx
https://www.exploit-db.com/exploits/32136

This is a fuzzer for CVE-2008-2321, targeting memory corruption vulnerabilities in the CoreGraphics component of Mac OS X. It tests various canvas operations to trigger potential exploits or denial-of-service conditions.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Apple Mac OS X v10.4.11 and prior, Mac OS X Server v10.4.11 and prior, Mac OS X v10.5.4 and prior, Mac OS X Server v10.5.4 and prior
No auth needed
Prerequisites: A vulnerable version of Mac OS X with a browser that supports the canvas element
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (15)

Core 15
Core References
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2009/jun/msg00002.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020603
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2008/Nov/msg00002.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2268
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1522
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3232
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30488
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35379
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT3318
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44127
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31326
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT3613
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30483
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32756

Scores

EPSS 0.1249
EPSS Percentile 95.7%

Details

CWE
CWE-399
Status published
Products (1)
apple/coregraphics
Published Aug 04, 2008
Tracked Since Feb 18, 2026