CVE-2008-1004: XSS
Published Mar 19, 2008
·Updated
Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the Web Inspector.
Affected Software
16 affected components
Safari=1.3.2
Safari=3.0.4
Safari=2.0.2
Safari=3.0.1
Safari=3.0.2
Safari=1.0
Safari=1.3
Safari=3.0.3
Safari=2.0
Safari=0.8
Safari=2.0.4
Safari=1.1
Safari=1.3.1
Safari=1.2
Safari=3.0
Safari=0.9
Remediation
Event History
Mar 19, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1004?
CVE-2008-1004 is classified as a medium severity vulnerability due to the potential for remote code execution via XSS attacks.
2
How do I fix CVE-2008-1004?
To mitigate CVE-2008-1004, users should upgrade to a patched version of Apple Safari that is newer than 3.1.
3
What type of vulnerability is CVE-2008-1004?
CVE-2008-1004 is a cross-site scripting (XSS) vulnerability affecting certain versions of Apple Safari.
4
Which versions of Safari are affected by CVE-2008-1004?
CVE-2008-1004 affects multiple versions of Apple Safari, including versions from 0.8 to 3.0.4.
5
What can attackers do with CVE-2008-1004?
Attackers exploiting CVE-2008-1004 can inject arbitrary web scripts or HTML into the affected versions of Safari.