Lucene search

K
cve[email protected]CVE-2008-4233
HistoryNov 25, 2008 - 11:30 p.m.

CVE-2008-4233

2008-11-2523:30:00
web.nvd.nist.gov
20
safari
apple
iphone
os
vulnerability
arbitrary phone call
crafted html

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

6.1 Medium

AI Score

Confidence

Low

0.02 Low

EPSS

Percentile

88.9%

Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not isolate the call-approval dialog from the process of launching new applications, which allows remote attackers to make arbitrary phone calls via a crafted HTML document.

Affected configurations

NVD
Node
appleipod_touch
OR
appleiphone_os
AND
applesafari
OR
appleiphone_osMatch1.0
OR
appleiphone_osMatch1.0.1
OR
appleiphone_osMatch1.0.2
OR
appleiphone_osMatch1.1
OR
appleiphone_osMatch1.1.1
OR
appleiphone_osMatch1.1.2
OR
appleiphone_osMatch1.1.3
OR
appleiphone_osMatch1.1.4
OR
appleiphone_osMatch1.1.5
OR
appleiphone_osMatch2.0
OR
appleiphone_osMatch2.0.1
OR
appleiphone_osMatch2.0.2
OR
appleiphone_osMatch2.1

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

6.1 Medium

AI Score

Confidence

Low

0.02 Low

EPSS

Percentile

88.9%

Related for CVE-2008-4233