Lucene search

K
cveMitreCVE-2008-1030
HistoryJun 02, 2008 - 9:30 p.m.

CVE-2008-1030

2008-06-0221:30:00
CWE-20
mitre
web.nvd.nist.gov
24
cve-2008-1030
integer overflow
cfdatareplacebytes
corefoundation
apple
mac os x
buffer overflow
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.003

Percentile

71.7%

Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial of service (crash) via an invalid length argument, which triggers a heap-based buffer overflow.

Affected configurations

Nvd
Node
applemac_os_xMatch10.4.11
OR
applemac_os_xMatch10.5
OR
applemac_os_xMatch10.5.1
OR
applemac_os_xMatch10.5.2
OR
applemac_os_x_serverMatch10.4.11
OR
applemac_os_x_serverMatch10.5
OR
applemac_os_x_serverMatch10.5.1
OR
applemac_os_x_serverMatch10.5.2
VendorProductVersionCPE
applemac_os_x10.4.11cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*
applemac_os_x10.5cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*
applemac_os_x10.5.1cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*
applemac_os_x10.5.2cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*
applemac_os_x_server10.4.11cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*
applemac_os_x_server10.5cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*
applemac_os_x_server10.5.1cpe:2.3:o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:*
applemac_os_x_server10.5.2cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.003

Percentile

71.7%