Apple Security Advisories · September 2008 — Apple Security Advisories
24 advisories 24 CVEs

Apple-vendor CVEs for 2008-09. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2008-3529

OtherWeaponized exploitHIGH2008-09-11

Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.

CVEs:CVE-2008-3529

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
mac_os_x affected apple
safari affected apple
Upstream advisory

CVE-2008-4116

OtherActive exploitation (sightings)HIGH2008-09-17

Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a long type attribute in a quicktime tag (1) on a web page or embedded in a (2) .mp4 or ...

CVEs:CVE-2008-4116

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
quicktime affected apple
Upstream advisory

CVE-2008-2326

OtherActive exploitation (sightings)HIGH2008-09-10

mDNSResponder in the Bonjour Namespace Provider in Apple Bonjour for Windows before 1.0.5 allows attackers to cause a denial of service (NULL pointer dereference and application crash) by resolving a crafted .local domain name that contains a long label.

CVEs:CVE-2008-2326

Affected products

ProductStatusVendorPackageEcosystem
bonjour affected apple
Upstream advisory

CVE-2008-3950

iOSActive exploitation (sightings)HIGH2008-09-16

Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod touch 1.1.4 and 2.0 allows remote attackers to cause a denial of service (browser crash) via a JavaScrip...

CVEs:CVE-2008-3950

Affected products

ProductStatusVendorPackageEcosystem
iphone affected apple
ipod_touch affected apple
safari affected apple
Upstream advisory

CVE-2008-3627

OtherEPSS <= 49%HIGH2008-09-10

Apple QuickTime before 7.5.5 does not properly handle (1) MDAT atoms in MP4 video files within QuickTimeH264.qtx, (2) MDAT atoms in mov video files within QuickTimeH264.scalar, and (3) AVC1 atoms in an unknown media type within an unspecified component...

CVEs:CVE-2008-3627

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2008-3625

OtherEPSS <= 49%HIGH2008-09-10

Stack-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a QuickTime Virtual Reality (QTVR) movie file with crafted (1) maxTilt, (2) minFieldOfVie...

CVEs:CVE-2008-3625

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2008-3635

OtherEPSS <= 49%HIGH2008-09-10

Stack-based buffer overflow in QuickTimeInternetExtras.qtx in an unspecified third-party Indeo v3.2 (aka IV32) codec for QuickTime, when used with Apple QuickTime before 7.5.5 on Windows, allows remote attackers to execute arbitrary code or cause a den...

CVEs:CVE-2008-3635

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2008-3632

iOSEPSS <= 49%HIGH2008-09-10

Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a web page with crafted Cascading Style S...

CVEs:CVE-2008-3632

Affected products

ProductStatusVendorPackageEcosystem
iphone affected apple
iphone_os affected apple
ipod_touch affected apple
Upstream advisory

CVE-2008-3637

macOSEPSS <= 49%HIGH2008-09-26

The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized variable, which allows remote attackers to execute arbitrary code via a crafted applet, related to an "error checking...

CVEs:CVE-2008-3637

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2008-3626

OtherEPSS <= 49%CRITICAL2008-09-10

The CallComponentFunctionWithStorage function in Apple QuickTime before 7.5.5 does not properly handle a large entry in the sample_size_table in STSZ atoms, which allows remote attackers to execute arbitrary code or cause a denial of service (memory co...

CVEs:CVE-2008-3626

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2008-3615

OtherEPSS <= 49%HIGH2008-09-10

ir50_32.qtx in an unspecified third-party Indeo v5 codec for QuickTime, when used with Apple QuickTime before 7.5.5 on Windows, accesses uninitialized memory, which allows remote attackers to execute arbitrary code or cause a denial of service (applica...

CVEs:CVE-2008-3615

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2008-3628

OtherEPSS <= 49%HIGH2008-09-10

Apple QuickTime before 7.5.5 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image, related to an "invalid pointer issue."

CVEs:CVE-2008-3628

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2008-3612

iOSEPSS <= 49%CRITICAL2008-09-10

The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which allows remote attackers to spoof or hijack a TCP connection.

CVEs:CVE-2008-3612

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2008-3638

macOSEPSS <= 49%HIGH2008-09-26

Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary programs.

CVEs:CVE-2008-3638

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2008-3624

OtherEPSS <= 49%CRITICAL2008-09-10

Heap-based buffer overflow in Apple QuickTime before 7.5.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a QuickTime Virtual Reality (QTVR) movie file with crafted panorama atoms.

CVEs:CVE-2008-3624

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2008-3631

iOSEPSS <= 49%CRITICAL2008-09-10

Application Sandbox in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, does not properly isolate third-party applications, which allows attackers to read arbitrary files in a third-party application's sandbox via a different third-par...

CVEs:CVE-2008-3631

Affected products

ProductStatusVendorPackageEcosystem
ipod_touch affected apple
Upstream advisory

CVE-2008-1739

OtherEPSS <= 49%CRITICAL2008-09-03

Apple QuickTime before 7.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted ftyp atoms in a movie file, which triggers memory corruption.

CVEs:CVE-2008-1739

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2008-3629

OtherEPSS <= 49%HIGH2008-09-10

Apple QuickTime before 7.5.5 allows remote attackers to cause a denial of service (application crash) via a crafted PICT image that triggers an out-of-bounds read.

CVEs:CVE-2008-3629

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2008-3618

macOSEPSS <= 49%HIGH2008-09-16

The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their own home directories are shared for their own use, which might allow attackers to leverage other vulner...

CVEs:CVE-2008-3618

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2008-3634

macOSEPSS <= 49%LOW2008-09-10

Apple iTunes before 8.0 on Mac OS X 10.4.11, when iTunes Music Sharing is enabled but blocked by the host-based firewall, presents misleading information about firewall security, which might allow remote attackers to leverage an exposure that would be ...

CVEs:CVE-2008-3634

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

CVE-2008-3630

OtherEPSS <= 49%CRITICAL2008-09-10

mDNSResponder in Apple Bonjour for Windows before 1.0.5, when an application uses the Bonjour API for unicast DNS, does not choose random values for transaction IDs or source ports in DNS requests, which makes it easier for remote attackers to spoof DN...

CVEs:CVE-2008-3630

Affected products

ProductStatusVendorPackageEcosystem
bonjour affected apple
Upstream advisory

CVE-2008-3617

macOSEPSS <= 49%MEDIUM2008-09-16

Remote Management and Screen Sharing in Apple Mac OS X 10.5 through 10.5.4, when used to set a password for a VNC viewer, displays additional input characters beyond the maximum password length, which might make it easier for attackers to guess passwor...

CVEs:CVE-2008-3617

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2008-3876

iOSEPSS <= 49%HIGH2008-09-02

Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an Emergency Call tap and a Home double-tap, followed by...

CVEs:CVE-2008-3876

Affected products

ProductStatusVendorPackageEcosystem
iphone affected apple
Upstream advisory

CVE-2008-3636

OtherEPSS <= 49%HIGH2008-09-10

Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: this issue was originally reported for GEARAspiWDM.sys 2.0.7.5 in Gear Soft...

CVEs:CVE-2008-3636

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.