CVE-2008-1999
Status: ModifiedMedium (5)—
Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.41%
- Percentile among all scored CVEs: 72
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://es.geocities.com/jplopezy/pruebasafari3.html
- http://secunia.com/advisories/29900
- http://securityreason.com/securityalert/3833
- http://www.securityfocus.com/archive/1/491192/100/0/threaded
- http://www.vupen.com/english/advisories/2008/1347
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41981
- http://es.geocities.com/jplopezy/pruebasafari3.html
- http://secunia.com/advisories/29900
- http://securityreason.com/securityalert/3833
- http://www.securityfocus.com/archive/1/491192/100/0/threaded
- http://www.vupen.com/english/advisories/2008/1347
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41981
Raw JSON (NVD)
Show
{
"id": "CVE-2008-1999",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-04-28T20:05:00.000",
"references": [
{
"url": "http://es.geocities.com/jplopezy/pruebasafari3.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/29900",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/3833",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/491192/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/1347",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41981",
"source": "cve@mitre.org"
},
{
"url": "http://es.geocities.com/jplopezy/pruebasafari3.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/29900",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/3833",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/491192/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/1347",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41981",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many \"invisible\" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences."
},
{
"lang": "es",
"value": "Apple Safari 3.1.1 permite a atacantes remotos falsificar la barra de direcciones colocando varios caracteres \"invisibles\" en el subcomponente userinfo del componente authority de la URL -también conocido como el fichero del usuario (user file)-; como se ha demostrado con las secuencias %E3%80%80."
}
],
"lastModified": "2026-06-16T22:52:54.600",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:3.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C453B588-15FD-4A9C-8BC1-6202A21DAE02"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}