{"api_version":"1","generated_at":"2026-07-23T08:25:49+00:00","cve":"CVE-2008-0046","urls":{"html":"https://cve.report/CVE-2008-0046","api":"https://cve.report/api/cve/CVE-2008-0046.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0046","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0046"},"summary":{"title":"CVE-2008-0046","description":"The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the \"Set access for specific services and applications\" radio button that might cause the user to believe that the button is used to restrict access only to specific services and applications, which might allow attackers to bypass intended access restrictions.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-03-18 22:44:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/29420","name":"http://secunia.com/advisories/29420","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://docs.info.apple.com/article.html?artnum=307562","name":"http://docs.info.apple.com/article.html?artnum=307562","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Security Update 2008-002","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html","name":"http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"APPLE-SA-2008-03-18 Security Update 2008-002","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/28304","name":"http://www.securityfocus.com/bid/28304","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RETIRED: Apple Mac OS X 2008-002 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1019658","name":"http://www.securitytracker.com/id?1019658","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mac OS X Application Firewall German Language Preference Panel May Mislead Users and Incorrectly Permit Services to Accept Connections - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA08-079A.html","name":"http://www.us-cert.gov/cas/techalerts/TA08-079A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA08-079A -- Apple Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41317","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41317","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/28368","name":"http://www.securityfocus.com/bid/28368","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple Mac OS X Application Firewall German Translation Insecure Configuration Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2008/0924/references","name":"http://www.vupen.com/english/advisories/2008/0924/references","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0046","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0046","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"46","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"46","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x_server","cpe6":"10.5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:32:23.334Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"macos-applicationfirewall-weak-security(41317)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41317"},{"name":"28304","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/28304"},{"name":"TA08-079A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-079A.html"},{"name":"ADV-2008-0924","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0924/references"},{"name":"29420","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29420"},{"name":"APPLE-SA-2008-03-18","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html"},{"name":"1019658","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1019658"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://docs.info.apple.com/article.html?artnum=307562"},{"name":"28368","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/28368"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-03-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the \"Set access for specific services and applications\" radio button that might cause the user to believe that the button is used to restrict access only to specific services and applications, which might allow attackers to bypass intended access restrictions."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"macos-applicationfirewall-weak-security(41317)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41317"},{"name":"28304","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/28304"},{"name":"TA08-079A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-079A.html"},{"name":"ADV-2008-0924","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0924/references"},{"name":"29420","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29420"},{"name":"APPLE-SA-2008-03-18","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html"},{"name":"1019658","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1019658"},{"tags":["x_refsource_CONFIRM"],"url":"http://docs.info.apple.com/article.html?artnum=307562"},{"name":"28368","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/28368"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-0046","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the \"Set access for specific services and applications\" radio button that might cause the user to believe that the button is used to restrict access only to specific services and applications, which might allow attackers to bypass intended access restrictions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"macos-applicationfirewall-weak-security(41317)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41317"},{"name":"28304","refsource":"BID","url":"http://www.securityfocus.com/bid/28304"},{"name":"TA08-079A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA08-079A.html"},{"name":"ADV-2008-0924","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0924/references"},{"name":"29420","refsource":"SECUNIA","url":"http://secunia.com/advisories/29420"},{"name":"APPLE-SA-2008-03-18","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html"},{"name":"1019658","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1019658"},{"name":"http://docs.info.apple.com/article.html?artnum=307562","refsource":"CONFIRM","url":"http://docs.info.apple.com/article.html?artnum=307562"},{"name":"28368","refsource":"BID","url":"http://www.securityfocus.com/bid/28368"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-0046","datePublished":"2008-03-18T22:00:00.000Z","dateReserved":"2008-01-03T00:00:00.000Z","dateUpdated":"2024-08-07T07:32:23.334Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-03-18 22:44:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*","matchCriteriaId":"B3267A41-1AE0-48B8-BD1F-DEC8A212851A"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*","matchCriteriaId":"C73BED9E-29FB-4965-B38F-013FFE5A9170"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"46","Ordinal":"1","Title":"CVE-2008-0046","CVE":"CVE-2008-0046","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"46","Ordinal":"1","NoteData":"The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the \"Set access for specific services and applications\" radio button that might cause the user to believe that the button is used to restrict access only to specific services and applications, which might allow attackers to bypass intended access restrictions.","Type":"Description","Title":"CVE-2008-0046"},{"CveYear":"2008","CveId":"46","Ordinal":"2","NoteData":"2008-03-18","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"46","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}