CVE-2008-1024 describes a memory corruption vulnerability in Apple Safari versions prior to 3.1.1, specifically when running on Windows XP or Vista. This flaw allows remote attackers to cause a denial of service (crash) and potentially execute arbitrary code through a crafted file name during a download. With a CVSS score of 6.8, this vulnerability is moderately severe, requiring user interaction (medium attack complexity) but allowing for partial impact to confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion beyond a single mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3CPE matchmatch criteria | cpe:2.3:a:apple:safari:3:*:*:*:*:*:*:* | ||
3.1CPE matchmatch criteria | cpe:2.3:a:apple:safari:3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.