First published: Wed Jan 16 2008(Updated: )
Unspecified vulnerability in Foundation, as used in Apple iPhone 1.0 through 1.1.2, iPod touch 1.1 through 1.1.2, and Mac OS X 10.5 through 10.5.1, allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted URL that triggers memory corruption in Safari.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.5 | |
Apple iOS and macOS | =10.5.1 | |
Apple iPhone | =1.0 | |
Apple iPhone | =1.02 | |
Apple iPod touch | =1.1 | |
Apple iPod touch | =1.1.1 | |
Apple iPod touch | =1.1.2 | |
iStyle @cosme iPhone OS | =1.0.1 | |
iStyle @cosme iPhone OS | =1.0.2 | |
iStyle @cosme iPhone OS | =1.1.1 | |
iStyle @cosme iPhone OS | =1.1.2 | |
Apple Mobile Safari |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0035 has a moderate severity as it can lead to denial of service or arbitrary code execution.
To fix CVE-2008-0035, users should ensure they are using updated versions of affected Apple software.
CVE-2008-0035 affects Apple iPhone OS versions 1.0 through 1.1.2, iPod touch up to 1.1.2, and Mac OS X 10.5 through 10.5.1.
Yes, CVE-2008-0035 can be exploited by remote attackers through crafted URLs.
CVE-2008-0035 involves memory corruption vulnerabilities that may lead to application termination.