CVE-2008-3644
Summary
| CVE | CVE-2008-3644 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-11-17 18:18:47 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser's page cache. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Safari | All | All | windows | All |
| Application | Apple | Safari | 0.8 | All | All | All |
| Application | Apple | Safari | 0.9 | All | All | All |
| Application | Apple | Safari | 1.0 | All | All | All |
| Application | Apple | Safari | 1.0 | beta | All | All |
| Application | Apple | Safari | 1.0 | beta2 | All | All |
| Application | Apple | Safari | 1.0.3 | All | All | All |
| Application | Apple | Safari | 1.1 | All | All | All |
| Application | Apple | Safari | 1.1.1 | All | All | All |
| Application | Apple | Safari | 1.2 | All | All | All |
| Application | Apple | Safari | 1.2.1 | All | All | All |
| Application | Apple | Safari | 1.2.2 | All | All | All |
| Application | Apple | Safari | 1.2.3 | All | All | All |
| Application | Apple | Safari | 1.2.4 | All | All | All |
| Application | Apple | Safari | 1.2.5 | All | All | All |
| Application | Apple | Safari | 1.3 | All | All | All |
| Application | Apple | Safari | 1.3.1 | All | All | All |
| Application | Apple | Safari | 1.3.2 | All | All | All |
| Application | Apple | Safari | 2 | All | All | All |
| Application | Apple | Safari | 2.0 | All | All | All |
| Application | Apple | Safari | 2.0.1 | All | All | All |
| Application | Apple | Safari | 2.0.2 | All | All | All |
| Application | Apple | Safari | 2.0.3 | All | All | All |
| Application | Apple | Safari | 2.0.3_417.9.3 | All | All | All |
| Application | Apple | Safari | 2.0.4 | All | All | All |
| Application | Apple | Safari | 2.0.4_419.3 | All | All | All |
| Application | Apple | Safari | 2.0_pre | All | All | All |
| Application | Apple | Safari | 3 | All | All | All |
| Application | Apple | Safari | 3.0 | All | All | All |
| Application | Apple | Safari | 3.0 | All | windows | All |
| Application | Apple | Safari | 3.0.1 | All | All | All |
| Application | Apple | Safari | 3.0.1 | All | windows | All |
| Application | Apple | Safari | 3.0.2 | All | All | All |
| Application | Apple | Safari | 3.0.2 | All | windows | All |
| Application | Apple | Safari | 3.0.3 | All | All | All |
| Application | Apple | Safari | 3.0.3 | All | windows | All |
| Application | Apple | Safari | 3.0.4 | All | All | All |
| Application | Apple | Safari | 3.0.4_beta | All | All | All |
| Application | Apple | Safari | 3.0.4_beta | All | windows | All |
| Application | Apple | Safari | 3.1 | All | All | All |
| Application | Apple | Safari | 3.1.1 | All | All | All |
| Application | Apple | Safari | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| About the security content of iPhone OS 2.2 and iPhone OS for iPod touch 2.2 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Apple iPhone / iPod touch Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| APPLE-SA-2008-11-13 Safari 3.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Vendor Advisory |
| About the security content of Safari 3.2 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Vendor Advisory |
| APPLE-SA-2008-11-20 iPhone OS 2.2 and iPhone OS for iPod touch 2.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Safari Form Autocomplete Feature May Disclose Information to Local Users - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Apple Safari Prior to 3.2 Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Apple Safari Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.