VDB
CVE-2008-3950
CVE-2008-3950
PUBLISHED
CVSS 5 MEDIUM
Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod touch 1.1.4 and 2.0 allows remote attackers to cause a denial of service (browser crash) via a JavaScript alert call with an argument that lacks breakable characters and has a length that is a multiple of the memory page size, leading to an out-of-bounds read.
EPSS 7.08% · 93.6th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
7.08%
93.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | safari | |
| n/a | n/a | n/a |
| apple | iphone | 2.0, 1.1.4 |
| apple | ipod_touch | 1.1.4, 2.0 |
Timeline
- Sep 12, 2008 PoC Published
- Sep 16, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 27, 2023 EPSS Score
- May 26, 2023 EPSS Score