CVE-2008-1036
The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character encodings, which might allow…
Does this matter?
Lower severity and a low EPSS score (3.19%). Track it; it rarely justifies an emergency change on its own.
Description
The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character encodings, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 3.19% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apple/mac os x · apple/mac os x server · redhat/enterprise linux
- Source
- cve@mitre.org
References
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/30430Vendor Advisory
- http://secunia.com/advisories/34290Vendor Advisory
- http://secunia.com/advisories/34777Vendor Advisory
- http://securitytracker.com/id?1020139
- http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0064
- http://www.debian.org/security/2009/dsa-1762
- http://www.redhat.com/support/errata/RHSA-2009-0296.html
- http://www.securityfocus.com/bid/29412
- http://www.securityfocus.com/bid/29488
- http://www.ubuntu.com/usn/USN-747-1
- http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlPatch, US Government Resource
- http://www.vupen.com/english/advisories/2008/1697Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42717
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10824
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/30430Vendor Advisory
- http://secunia.com/advisories/34290Vendor Advisory
- http://secunia.com/advisories/34777Vendor Advisory
- http://securitytracker.com/id?1020139
- http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0064
- http://www.debian.org/security/2009/dsa-1762
- http://www.redhat.com/support/errata/RHSA-2009-0296.html
- http://www.securityfocus.com/bid/29412
- http://www.securityfocus.com/bid/29488
- http://www.ubuntu.com/usn/USN-747-1
- http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlPatch, US Government Resource
- http://www.vupen.com/english/advisories/2008/1697Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42717
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10824
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.