CVE-2008-4232
Estado: ModificadaMedia (5)—
Safari en Apple iPhone OS 2.0 hasta 2.1 y iPhone OS para iPod touch 2.1 no restringe mostrar contenidos IFRAME para los límites del IFRAME, el cual permite a los atacantes remotos espiar una interfaz de usuario a través de documentos HTML manipulados.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.16%
- Percentil entre todas las CVEs puntuadas: 82
- Fecha de la puntuación: 9/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-Other
Referencias
- http://lists.apple.com/archives/security-announce/2008/Nov/msg00002.html
- http://osvdb.org/50029
- http://secunia.com/advisories/32756
- http://support.apple.com/kb/HT3318
- http://www.securityfocus.com/bid/32394
- http://www.securitytracker.com/id?1021272
- http://www.vupen.com/english/advisories/2008/3232
- http://lists.apple.com/archives/security-announce/2008/Nov/msg00002.html
- http://osvdb.org/50029
- http://secunia.com/advisories/32756
- http://support.apple.com/kb/HT3318
- http://www.securityfocus.com/bid/32394
- http://www.securitytracker.com/id?1021272
- http://www.vupen.com/english/advisories/2008/3232
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-4232",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-11-25T23:30:00.453",
"references": [
{
"url": "http://lists.apple.com/archives/security-announce/2008/Nov/msg00002.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/50029",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/32756",
"source": "cve@mitre.org"
},
{
"url": "http://support.apple.com/kb/HT3318",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/32394",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1021272",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/3232",
"source": "cve@mitre.org"
},
{
"url": "http://lists.apple.com/archives/security-announce/2008/Nov/msg00002.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/50029",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/32756",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://support.apple.com/kb/HT3318",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/32394",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1021272",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/3232",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundaries of the IFRAME, which allows remote attackers to spoof a user interface via a crafted HTML document."
},
{
"lang": "es",
"value": "Safari en Apple iPhone OS 2.0 hasta 2.1 y iPhone OS para iPod touch 2.1 no restringe mostrar contenidos IFRAME para los límites del IFRAME, el cual permite a los atacantes remotos espiar una interfaz de usuario a través de documentos HTML manipulados."
}
],
"lastModified": "2026-06-16T22:57:27.870",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:apple:ipod_touch:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "88FA2602-DDAB-4E23-A3D2-FB712970AAD1"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "340C4071-1447-477F-942A-8E09EA29F917"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE370CAA-04B3-434E-BD5B-1D87DE596C10"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41DB23F0-7226-4D0B-A3FA-A801F02EBA6B"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0C5B94E7-2C24-4913-B65E-8D8A0DE2B80B"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E28FB0CB-D636-4F85-B5F7-70EC30053925"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4AEDE82-E317-4066-A34F-BB3BCD3F53E2"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "27319629-171F-42AA-A95F-2D71F78097D0"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4F7AEFAB-7BB0-40D8-8BA5-71B374EB69DB"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "297F9438-0F04-4128-94A8-A504B600929E"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F8618621-F871-4531-9F6C-7D60F2BF8B75"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:1.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "824DED2D-FA1D-46FC-8252-6E25546DAE29"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1641DDFA-3BF1-467F-8EC3-98114FF9F07B"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D61644E2-7AF5-48EF-B3D5-59C7B2AD1A58"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3D06D54D-97FD-49FD-B251-CC86FBA68CA6"
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:2.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "25A5D868-0016-44AB-80E6-E5DF91F15455"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}