{"api_version":"1","generated_at":"2026-07-23T06:11:38+00:00","cve":"CVE-2008-2540","urls":{"html":"https://cve.report/CVE-2008-2540","api":"https://cve.report/api/cve/CVE-2008-2540.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-2540","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-2540"},"summary":{"title":"CVE-2008-2540","description":"Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a \"Carpet Bomb\" and a \"Blended Threat Elevation of Privilege Vulnerability,\" a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-06-03 15:32:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.dhanjani.com/archives/2008/05/safari_carpet_bomb.html","name":"http://www.dhanjani.com/archives/2008/05/safari_carpet_bomb.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Access denied | www.dhanjani.com used Cloudflare to restrict access","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm","name":"http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"ASA-2009-133 (963027)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-014","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-014","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS09-014 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1022047","name":"http://www.securitytracker.com/id?1022047","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Microsoft Windows SearchPath Function May Let Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2008//Jun/msg00001.html","name":"http://lists.apple.com/archives/security-announce/2008//Jun/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Vendor Advisory"],"title":"APPLE-SA-2008-06-19 Safari v3.1.2 for Windows","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/1706","name":"http://www.vupen.com/english/advisories/2008/1706","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=871138","name":"http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=871138","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://blogs.zdnet.com/security/?p=1230","name":"http://blogs.zdnet.com/security/?p=1230","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Microsoft issues Safari-to-IE blended threat warning | Zero Day \r\n\t\t| ZDNet.com","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42765","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42765","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8509","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8509","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA09-104A.html","name":"http://www.us-cert.gov/cas/techalerts/TA09-104A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA09-104A -- Microsoft Updates for Multiple Vulnerabilities","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/1028","name":"http://www.vupen.com/english/advisories/2009/1028","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://aviv.raffon.net/2008/05/31/SafariPwnsInternetExplorer.aspx","name":"http://aviv.raffon.net/2008/05/31/SafariPwnsInternetExplorer.aspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Aviv Raff On .NET - Safari pwns Internet Explorer","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5782","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5782","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6108","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6108","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/1029","name":"http://www.vupen.com/english/advisories/2009/1029","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1020150","name":"http://securitytracker.com/id?1020150","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - Apple Safari for Windows XP and Vista Lets Remote Users Download Files","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.microsoft.com/technet/security/advisory/953818.mspx","name":"http://www.microsoft.com/technet/security/advisory/953818.mspx","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Patch","Vendor Advisory"],"title":"Your request has been blocked. This could be\r\n                        due to several reasons.","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/29445","name":"http://www.securityfocus.com/bid/29445","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Apple Safari and Microsoft Windows Client-side Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/30467","name":"http://secunia.com/advisories/30467","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Apple Safari on Windows Code Execution Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-015","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-015","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS09-015 - Moderate | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-2540","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-2540","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"2540","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"safari","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2540","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"internet_explorer","cpe6":"7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2540","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2003","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2540","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_server_2008","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2540","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_vista","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"2540","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:05:30.232Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"30467","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30467"},{"name":"ADV-2009-1028","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/1028"},{"name":"1022047","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1022047"},{"name":"1020150","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1020150"},{"name":"29445","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/29445"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.microsoft.com/technet/security/advisory/953818.mspx"},{"name":"ADV-2009-1029","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/1029"},{"name":"TA09-104A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA09-104A.html"},{"name":"oval:org.mitre.oval:def:8509","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8509"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://blogs.zdnet.com/security/?p=1230"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=871138"},{"name":"MS09-014","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-014"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.dhanjani.com/archives/2008/05/safari_carpet_bomb.html"},{"name":"APPLE-SA-2008-06-19","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2008//Jun/msg00001.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://aviv.raffon.net/2008/05/31/SafariPwnsInternetExplorer.aspx"},{"name":"oval:org.mitre.oval:def:5782","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5782"},{"name":"apple-safari-windows-code-execution(42765)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42765"},{"name":"MS09-015","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-015"},{"name":"oval:org.mitre.oval:def:6108","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6108"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm"},{"name":"ADV-2008-1706","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/1706"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-05-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a \"Carpet Bomb\" and a \"Blended Threat Elevation of Privilege Vulnerability,\" a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"30467","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30467"},{"name":"ADV-2009-1028","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/1028"},{"name":"1022047","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1022047"},{"name":"1020150","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1020150"},{"name":"29445","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/29445"},{"tags":["x_refsource_MISC"],"url":"http://www.microsoft.com/technet/security/advisory/953818.mspx"},{"name":"ADV-2009-1029","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/1029"},{"name":"TA09-104A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA09-104A.html"},{"name":"oval:org.mitre.oval:def:8509","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8509"},{"tags":["x_refsource_MISC"],"url":"http://blogs.zdnet.com/security/?p=1230"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=871138"},{"name":"MS09-014","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-014"},{"tags":["x_refsource_MISC"],"url":"http://www.dhanjani.com/archives/2008/05/safari_carpet_bomb.html"},{"name":"APPLE-SA-2008-06-19","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2008//Jun/msg00001.html"},{"tags":["x_refsource_MISC"],"url":"http://aviv.raffon.net/2008/05/31/SafariPwnsInternetExplorer.aspx"},{"name":"oval:org.mitre.oval:def:5782","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5782"},{"name":"apple-safari-windows-code-execution(42765)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42765"},{"name":"MS09-015","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-015"},{"name":"oval:org.mitre.oval:def:6108","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6108"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm"},{"name":"ADV-2008-1706","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/1706"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-2540","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a \"Carpet Bomb\" and a \"Blended Threat Elevation of Privilege Vulnerability,\" a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"30467","refsource":"SECUNIA","url":"http://secunia.com/advisories/30467"},{"name":"ADV-2009-1028","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/1028"},{"name":"1022047","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1022047"},{"name":"1020150","refsource":"SECTRACK","url":"http://securitytracker.com/id?1020150"},{"name":"29445","refsource":"BID","url":"http://www.securityfocus.com/bid/29445"},{"name":"http://www.microsoft.com/technet/security/advisory/953818.mspx","refsource":"MISC","url":"http://www.microsoft.com/technet/security/advisory/953818.mspx"},{"name":"ADV-2009-1029","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/1029"},{"name":"TA09-104A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA09-104A.html"},{"name":"oval:org.mitre.oval:def:8509","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8509"},{"name":"http://blogs.zdnet.com/security/?p=1230","refsource":"MISC","url":"http://blogs.zdnet.com/security/?p=1230"},{"name":"http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=871138","refsource":"CONFIRM","url":"http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=871138"},{"name":"MS09-014","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-014"},{"name":"http://www.dhanjani.com/archives/2008/05/safari_carpet_bomb.html","refsource":"MISC","url":"http://www.dhanjani.com/archives/2008/05/safari_carpet_bomb.html"},{"name":"APPLE-SA-2008-06-19","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2008//Jun/msg00001.html"},{"name":"http://aviv.raffon.net/2008/05/31/SafariPwnsInternetExplorer.aspx","refsource":"MISC","url":"http://aviv.raffon.net/2008/05/31/SafariPwnsInternetExplorer.aspx"},{"name":"oval:org.mitre.oval:def:5782","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5782"},{"name":"apple-safari-windows-code-execution(42765)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42765"},{"name":"MS09-015","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-015"},{"name":"oval:org.mitre.oval:def:6108","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6108"},{"name":"http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm","refsource":"CONFIRM","url":"http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm"},{"name":"ADV-2008-1706","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/1706"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-2540","datePublished":"2008-06-03T15:00:00.000Z","dateReserved":"2008-06-03T00:00:00.000Z","dateUpdated":"2024-08-07T09:05:30.232Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-06-03 15:32:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*","versionEndExcluding":"3.1.2","matchCriteriaId":"203C193C-F044-4B1F-84E6-2AB332AF581B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:*","matchCriteriaId":"1A33FA7F-BB2A-4C66-B608-72997A2BD1DB"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:*:*","matchCriteriaId":"31A64C69-D182-4BEC-BA8A-7B405F5B2FC0"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_server_2008:*:*:*:*:*:*:*:*","matchCriteriaId":"6B33C9BD-FC34-4DFC-A81F-C620D3DAA79D"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*","matchCriteriaId":"7CAEEA81-5037-4B68-98D9-83AAEBC98E20"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:*","matchCriteriaId":"B47EBFCC-1828-45AB-BC6D-FB980929A81A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"2540","Ordinal":"1","Title":"CVE-2008-2540","CVE":"CVE-2008-2540","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"2540","Ordinal":"1","NoteData":"Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a \"Carpet Bomb\" and a \"Blended Threat Elevation of Privilege Vulnerability,\" a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.","Type":"Description","Title":"CVE-2008-2540"},{"CveYear":"2008","CveId":"2540","Ordinal":"2","NoteData":"2008-06-03","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"2540","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}