Apple Security Advisories · July 2008 — Apple Security Advisories
12 advisories 12 CVEs

Apple-vendor CVEs for 2008-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2008-2304

XcodeActive exploitation (sightings)CRITICAL2008-07-14

Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a .funhouse file with a string X...

CVEs:CVE-2008-2304

Affected products

ProductStatusVendorPackageEcosystem
core_image_fun_house affected apple
Upstream advisory

CVE-2008-2934

macOSEPSS <= 49%CRITICAL2008-07-17

Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.

CVEs:CVE-2008-2934

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2008-2311

macOSEPSS <= 49%CRITICAL2008-07-01

Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a downloaded file.

CVEs:CVE-2008-2311

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2008-2309

macOSEPSS <= 49%CRITICAL2008-07-01

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsafe" warning message in (a) the D...

CVEs:CVE-2008-2309

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2008-2310

macOSEPSS <= 49%CRITICAL2008-07-01

Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.

CVEs:CVE-2008-2310

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2008-1588

iOSEPSS <= 49%MEDIUM2008-07-14

Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to spoof the address bar via Unicode ideographic spaces in the URL.

CVEs:CVE-2008-1588

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2008-3170

SafariEPSS <= 49%MEDIUM2008-07-14

Apple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cooking," a related...

CVEs:CVE-2008-3170

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2008-2318

XcodeEPSS <= 49%HIGH2008-07-14

The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the requests for these URLs.

CVEs:CVE-2008-2318

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
xcode_tools affected apple
Upstream advisory

CVE-2008-3171

SafariEPSS <= 49%HIGH2008-07-14

Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.

CVEs:CVE-2008-3171

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2008-2313

macOSEPSS <= 49%MEDIUM2008-07-01

Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local users to gain privileges by inserting a Trojan horse file into this directory.

CVEs:CVE-2008-2313

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2008-2308

macOSEPSS <= 49%HIGH2008-07-01

Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms allows local users to gain privileges or cause a denial of service (memory corruption and application crash) by resolving an alias that contains crafted ...

CVEs:CVE-2008-2308

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2008-2314

macOSEPSS <= 49%MEDIUM2008-07-01

Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically proximate attackers to gain access to a locked session in (1) sleep mode or (2) screen saver mode via unspecified vectors.

CVEs:CVE-2008-2314

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.