Apple Security Advisories · August 2008 — Apple Security Advisories
10 advisories 10 CVEs

Apple-vendor CVEs for 2008-08. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2008-2939

OtherPoC exploitCRITICAL2008-08-05

Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web ...

CVEs:CVE-2008-2939

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2008-3281

OtherPoC exploitHIGH2008-08-27

libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.

CVEs:CVE-2008-3281

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2008-2324

macOSPoC exploitMEDIUM2008-08-01

The Repair Permissions tool in Disk Utility in Apple Mac OS X 10.4.11 adds the setuid bit to the emacs executable file, which allows local users to gain privileges by executing commands within emacs.

CVEs:CVE-2008-2324

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2008-2321

macOSEPSS <= 49%HIGH2008-08-01

Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unknown vectors involving "processing of argumen...

CVEs:CVE-2008-2321

Affected products

ProductStatusVendorPackageEcosystem
coregraphics affected apple
Upstream advisory

CVE-2008-2322

macOSEPSS <= 49%HIGH2008-08-01

Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11, 10.5.2, and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF file with a long Type 1 font, which triggers a heap-based buffer...

CVEs:CVE-2008-2322

Affected products

ProductStatusVendorPackageEcosystem
coregraphics affected apple
Upstream advisory

CVE-2008-2325

macOSEPSS <= 49%HIGH2008-08-01

QuickLook in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office file, related to insufficient "bounds checking."

CVEs:CVE-2008-2325

Affected products

ProductStatusVendorPackageEcosystem
quicklook affected apple
Upstream advisory

CVE-2008-2320

macOSEPSS <= 49%HIGH2008-08-01

Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows context-dependent attackers to execute arbitrary code or cause a denial of service (appli...

CVEs:CVE-2008-2320

Affected products

ProductStatusVendorPackageEcosystem
carboncore affected apple
Upstream advisory

CVE-2008-3434

OtherEPSS <= 49%CRITICAL2008-08-01

Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

CVEs:CVE-2008-3434

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2008-2323

macOSEPSS <= 49%CRITICAL2008-08-01

Unspecified vulnerability in Data Detectors Engine in Apple Mac OS X 10.5.4 allows attackers to cause a denial of service (resource consumption) via crafted textual content in messages.

CVEs:CVE-2008-2323

Affected products

ProductStatusVendorPackageEcosystem
data_detectors_engine affected apple
Upstream advisory

CVE-2008-3438

macOSEPSS <= 49%CRITICAL2008-08-01

Apple Mac OS X does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

CVEs:CVE-2008-3438

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.