Lucene search

K
cveMitreCVE-2008-1026
HistoryApr 17, 2008 - 7:05 p.m.

CVE-2008-1026

2008-04-1719:05:00
CWE-119
mitre
web.nvd.nist.gov
25
cve
integer overflow
pcre
apple webkit
safari
code execution
buffer overflow

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.099

Percentile

94.9%

Integer overflow in the PCRE regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to execute arbitrary code via a regular expression with large, nested repetition counts, which triggers a heap-based buffer overflow.

Affected configurations

Nvd
Node
applemac_os_xMatch10.4.11
OR
applemac_os_xMatch10.5.2
OR
applemac_os_x_serverMatch10.4.11
OR
applemac_os_x_serverMatch10.5.2
OR
microsoftwindows_vista
OR
microsoftwindows_xp
AND
applesafariMatch3
OR
applesafariMatch3.1
VendorProductVersionCPE
applesafari3.1cpe:/a:apple:safari:3.1:::
applesafari3cpe:/a:apple:safari:3:::

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.5

Confidence

Low

EPSS

0.099

Percentile

94.9%