{"api_version":"1","generated_at":"2026-07-23T05:39:19+00:00","cve":"CVE-2008-1999","urls":{"html":"https://cve.report/CVE-2008-1999","api":"https://cve.report/api/cve/CVE-2008-1999.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-1999","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-1999"},"summary":{"title":"CVE-2008-1999","description":"Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many \"invisible\" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-04-28 20:05:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2008/1347","name":"http://www.vupen.com/english/advisories/2008/1347","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/29900","name":"http://secunia.com/advisories/29900","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Safari Address Bar URL Spoofing Security Issue - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/3833","name":"http://securityreason.com/securityalert/3833","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41981","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41981","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/491192/100/0/threaded","name":"http://www.securityfocus.com/archive/1/491192/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://es.geocities.com/jplopezy/pruebasafari3.html","name":"http://es.geocities.com/jplopezy/pruebasafari3.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Could Not Connect","mime":"text/html","httpstatus":"502","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-1999","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-1999","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"1999","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"safari","cpe6":"3.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T08:41:00.241Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2008-1347","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/1347"},{"name":"apple-safari-user-addressbar-spoofing(41981)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41981"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://es.geocities.com/jplopezy/pruebasafari3.html"},{"name":"20080422 Safari 3.1.1 Multiple Vulnerabilities for windows","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/491192/100/0/threaded"},{"name":"3833","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3833"},{"name":"29900","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29900"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-04-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many \"invisible\" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2008-1347","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/1347"},{"name":"apple-safari-user-addressbar-spoofing(41981)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41981"},{"tags":["x_refsource_MISC"],"url":"http://es.geocities.com/jplopezy/pruebasafari3.html"},{"name":"20080422 Safari 3.1.1 Multiple Vulnerabilities for windows","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/491192/100/0/threaded"},{"name":"3833","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3833"},{"name":"29900","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29900"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-1999","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many \"invisible\" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2008-1347","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/1347"},{"name":"apple-safari-user-addressbar-spoofing(41981)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41981"},{"name":"http://es.geocities.com/jplopezy/pruebasafari3.html","refsource":"MISC","url":"http://es.geocities.com/jplopezy/pruebasafari3.html"},{"name":"20080422 Safari 3.1.1 Multiple Vulnerabilities for windows","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/491192/100/0/threaded"},{"name":"3833","refsource":"SREASON","url":"http://securityreason.com/securityalert/3833"},{"name":"29900","refsource":"SECUNIA","url":"http://secunia.com/advisories/29900"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-1999","datePublished":"2008-04-28T18:21:00.000Z","dateReserved":"2008-04-28T00:00:00.000Z","dateUpdated":"2024-08-07T08:41:00.241Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-04-28 20:05:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:safari:3.1.1:*:*:*:*:*:*:*","matchCriteriaId":"C453B588-15FD-4A9C-8BC1-6202A21DAE02"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"1999","Ordinal":"1","Title":"CVE-2008-1999","CVE":"CVE-2008-1999","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"1999","Ordinal":"1","NoteData":"Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many \"invisible\" characters in the userinfo subcomponent of the authority component of the URL (aka the user field), as demonstrated by %E3%80%80 sequences.","Type":"Description","Title":"CVE-2008-1999"},{"CveYear":"2008","CveId":"1999","Ordinal":"2","NoteData":"2008-04-28","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"1999","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}