CVE-2008-4232

Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundaries of the IFRAME, which allows remote attackers to spoof a user interface via a crafted HTML document.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:h:apple:ipod_touch:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:2.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:2.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:51

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2008/Nov/msg00002.html - Vendor Advisory () http://lists.apple.com/archives/security-announce/2008/Nov/msg00002.html - Vendor Advisory
References () http://osvdb.org/50029 - () http://osvdb.org/50029 -
References () http://secunia.com/advisories/32756 - () http://secunia.com/advisories/32756 -
References () http://support.apple.com/kb/HT3318 - Vendor Advisory () http://support.apple.com/kb/HT3318 - Vendor Advisory
References () http://www.securityfocus.com/bid/32394 - () http://www.securityfocus.com/bid/32394 -
References () http://www.securitytracker.com/id?1021272 - () http://www.securitytracker.com/id?1021272 -
References () http://www.vupen.com/english/advisories/2008/3232 - () http://www.vupen.com/english/advisories/2008/3232 -

Information

Published : 2008-11-25 23:30

Updated : 2024-11-21 00:51


NVD link : CVE-2008-4232

Mitre link : CVE-2008-4232

CVE.ORG link : CVE-2008-4232


JSON object : View

Products Affected

apple

  • iphone_os
  • safari
  • ipod_touch