CVE-2008-2540
Summary
| CVE | CVE-2008-2540 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-06-03 15:32:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Safari | All | All | All | All |
| Application | Microsoft | Internet Explorer | 7 | All | All | All |
| Operating System | Microsoft | Windows Server 2003 | All | All | All | All |
| Operating System | Microsoft | Windows Server 2008 | All | All | All | All |
| Operating System | Microsoft | Windows Vista | - | All | All | All |
| Operating System | Microsoft | Windows Xp | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Access denied | www.dhanjani.com used Cloudflare to restrict access | af854a3a-2127-422b-91ae-364da2661108 | www.dhanjani.com | Broken Link |
| ASA-2009-133 (963027) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | Third Party Advisory |
| Microsoft Security Bulletin MS09-014 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| Microsoft Windows SearchPath Function May Let Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| APPLE-SA-2008-06-19 Safari v3.1.2 for Windows | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Mailing List, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| support.nortel.com/go/main.jsp | af854a3a-2127-422b-91ae-364da2661108 | support.nortel.com | Third Party Advisory |
| Microsoft issues Safari-to-IE blended threat warning | Zero Day | ZDNet.com | af854a3a-2127-422b-91ae-364da2661108 | blogs.zdnet.com | Third Party Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Third Party Advisory |
| US-CERT Technical Cyber Security Alert TA09-104A -- Microsoft Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Third Party Advisory, US Government Resource |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| Aviv Raff On .NET - Safari pwns Internet Explorer | af854a3a-2127-422b-91ae-364da2661108 | aviv.raffon.net | Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Third Party Advisory |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Third Party Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Broken Link |
| SecurityTracker.com Archives - Apple Safari for Windows XP and Vista Lets Remote Users Download Files | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Third Party Advisory, VDB Entry |
| Your request has been blocked. This could be due to several reasons. | af854a3a-2127-422b-91ae-364da2661108 | www.microsoft.com | Mitigation, Patch, Vendor Advisory |
| Apple Safari and Microsoft Windows Client-side Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Apple Safari on Windows Code Execution Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Third Party Advisory |
| Microsoft Security Bulletin MS09-015 - Moderate | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.