Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2008-1580

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Mac OS X是苹果家族机器所使用的操作系统。 Apple Mac 操作系统 10.5.3 之前的 X 版本的Safari CFNetwork自动发送SSl 客户端证书来响应Web服务器的证书请求,导致远程网站可以从个人身份证书获取敏感信息(主题数据),并使用任意证书跨域跟踪用户的活动。

AI Predicted 5.9 Difficulty: Trivial EPSS 1.30% · P68
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2008-1580

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
CFNetwork in Safari in Apple Mac OS X before 10.5.3 automatically sends an SSL client certificate in response to a web server's certificate request, which allows remote web sites to obtain sensitive information (Subject data) from personally identifiable certificates, and use arbitrary certificates to track user activities across domains, a related issue to CVE-2007-4879.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Apple Mac OS X Safari CFNetwork 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mac OS X是苹果家族机器所使用的操作系统。 Apple Mac 操作系统 10.5.3 之前的 X 版本的Safari CFNetwork自动发送SSl 客户端证书来响应Web服务器的证书请求,导致远程网站可以从个人身份证书获取敏感信息(主题数据),并使用任意证书跨域跟踪用户的活动。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2008-1580

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-1580

登录查看更多情报信息。

Vendor Advisories for CVE-2008-1580 (7)

Mailing List Discussions for CVE-2008-1580 (1)

Same Patch Batch · n/a · 2008-06-02 · 28 CVEs total

CVE-2008-1576 Apple Mac OS X Mail 未初始化缓冲区错误漏洞
CVE-2008-2515 IBM AIX 'iostat' 本地特权提升漏洞
CVE-2008-2514 IBM AIX 'errpt' 本地缓冲区溢出漏洞
CVE-2008-2513 IBM AIX 内核缓冲区溢出漏洞
CVE-2008-2512 Symantec Backup Exec 未明目录遍历漏洞
CVE-2008-2511 CA Internet安全套装 UmxEventCli.dll 目录遍历漏洞
CVE-2008-2426 imlib2库多个栈溢出漏洞
CVE-2008-2363 Pan .nzb文件解析堆溢出漏洞
CVE-2008-2359 Redhat Fedora_8 配置错误漏洞
CVE-2008-2099 VMware VMCI功能任意代码执行漏洞
CVE-2008-2098 VMware HGFS文件系统堆溢出漏洞
CVE-2008-1579 Apple Mac OS X Wiki服务器信息泄露漏洞
CVE-2008-1578 Apple Mac OS X sso_util命令行工具信息泄露漏洞
CVE-2008-1577 Apple Mac OS X Apple Pixlet 视频Pixlet 编解码器未明漏洞
CVE-2008-1027 Apple Mac OS X FTP共享文件夹权限许可和访问控制漏洞
CVE-2008-1575 Apple Mac OS X ATS 服务未明漏洞
CVE-2008-1574 Apple Mac OS X JPEG2000图形文件整数溢出漏洞
CVE-2008-1573 Apple Mac OS X 缓冲区溢出漏洞
CVE-2008-1572 Apple Mac OS X 图片捕获权限许可和访问控制漏洞
CVE-2008-1571 Apple Mac OS X 图片捕获目录遍历漏洞

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-1580

No comments yet


Leave a comment