Vulnerability Name:
CCN-52951
Published:
2009-08-31
Updated:
2009-08-31
Summary:
Apple iPhone and iTouch are vulnerable to a denial of service. By persuading a user to open a specially-crafted Web page with MobileSafari browser, a remote attacker could exploit this vulnerability to cause the device to reboot.
CVSS v3 Severity:
7.5 High
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
High
CVSS v2 Severity:
7.1 High
(CCN CVSS v2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:C
)
6.8 Medium
(CCN Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:C/E:H/RL:U/RC:UR
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
None
Integrity (I):
None
Availibility (A):
Complete
Vulnerability Consequences:
Denial of Service
References:
Source: CCN
Type: Apple Web site
Apple iPhone
Source: CCN
Type: BID-36195
Apple iPhone and iPod touch Mobile Safari Alert Remote Denial of Service Vulnerability
Source: XF
Type: UNKNOWN
ipod-itouch-mobilesafari-dos(52951)
Vulnerable Configuration:
Configuration CCN 1
:
cpe:/o:apple:iphone_os:1.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.3:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.0.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.0.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:1.1:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:1.1.1:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:1.1.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1.4:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:1.1.3:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:1.1.4:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0.2:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:2.0.2:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:2.0.1:*:*:*:*:*:*:*
OR
cpe:/h:apple:ipod_touch:2.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.0.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:1.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:3.0:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.2:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:2.2.1:*:*:*:*:*:*:*
OR
cpe:/o:apple:iphone_os:3.0.1:*:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
apple
iphone 1.0
apple
iphone 1.1.2
apple
iphone 1.1.3
apple
iphone 1.0.1
apple
iphone 1.0.2
apple
iphone 1.1.1
apple
ipod touch 1.1
apple
ipod touch 1.1.1
apple
ipod touch 1.1.2
apple
iphone 1.1.4
apple
ipod touch 1.1.3
apple
ipod touch 1.1.4
apple
iphone 2.0.2
apple
ipod touch 2.0.2
apple
ipod touch 2.0.1
apple
ipod touch 2.0
apple
iphone 2.0
apple
iphone 2.0.1
apple
iphone 2.1
apple
iphone 1.1
apple
iphone os 3.0
apple
iphone os 2.2
apple
iphone os 2.2.1
apple
iphone os 3.0.1