{"api_version":"1","generated_at":"2026-07-23T11:57:02+00:00","cve":"CVE-2008-3618","urls":{"html":"https://cve.report/CVE-2008-3618","api":"https://cve.report/api/cve/CVE-2008-3618.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3618","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3618"},"summary":{"title":"CVE-2008-3618","description":"The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their own home directories are shared for their own use, which might allow attackers to leverage other vulnerabilities and access files for which sharing was unintended.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-09-16 23:00:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9","severity":"","vector":"AV:N/AC:L/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://securitytracker.com/id?1020883","name":"http://securitytracker.com/id?1020883","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mac OS X System Preferences File Sharing Pane Does Not Fully Display the Users Access Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/126787","name":"http://www.kb.cert.org/vuls/id/126787","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","US Government Resource"],"title":"US-CERT Vulnerability Note VU#126787","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html","name":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"APPLE-SA-2008-09-15 Mac OS X v10.5.5 and Security Update 2008-006","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/31189","name":"http://www.securityfocus.com/bid/31189","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Apple Mac OS X 2008-006 Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2008/2584","name":"http://www.vupen.com/english/advisories/2008/2584","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA08-260A.html","name":"http://www.us-cert.gov/cas/techalerts/TA08-260A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA08-260A -- Apple Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45175","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45175","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3618","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3618","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3618","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3618","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3618","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.5.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3618","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.5.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3618","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"mac_os_x","cpe6":"10.5.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:45:19.001Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"31189","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31189"},{"name":"VU#126787","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/126787"},{"name":"APPLE-SA-2008-09-15","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html"},{"name":"TA08-260A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-260A.html"},{"name":"ADV-2008-2584","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/2584"},{"name":"1020883","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1020883"},{"name":"macos-filesharing-weak-security(45175)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45175"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-09-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their own home directories are shared for their own use, which might allow attackers to leverage other vulnerabilities and access files for which sharing was unintended."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"31189","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31189"},{"name":"VU#126787","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/126787"},{"name":"APPLE-SA-2008-09-15","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html"},{"name":"TA08-260A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-260A.html"},{"name":"ADV-2008-2584","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/2584"},{"name":"1020883","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1020883"},{"name":"macos-filesharing-weak-security(45175)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45175"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3618","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their own home directories are shared for their own use, which might allow attackers to leverage other vulnerabilities and access files for which sharing was unintended."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"31189","refsource":"BID","url":"http://www.securityfocus.com/bid/31189"},{"name":"VU#126787","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/126787"},{"name":"APPLE-SA-2008-09-15","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html"},{"name":"TA08-260A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA08-260A.html"},{"name":"ADV-2008-2584","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/2584"},{"name":"1020883","refsource":"SECTRACK","url":"http://securitytracker.com/id?1020883"},{"name":"macos-filesharing-weak-security(45175)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/45175"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3618","datePublished":"2008-09-16T23:00:00.000Z","dateReserved":"2008-08-12T00:00:00.000Z","dateUpdated":"2024-08-07T09:45:19.001Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-09-16 23:00:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*","matchCriteriaId":"D2442D35-7484-43D8-9077-3FDF63104816"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*","matchCriteriaId":"3F3E721C-00CA-4D51-B542-F2BC5C0D65BF"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*","matchCriteriaId":"B3267A41-1AE0-48B8-BD1F-DEC8A212851A"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.5.3:*:*:*:*:*:*:*","matchCriteriaId":"855288F1-0242-4951-AB3F-B7AF13E21CF6"},{"vulnerable":true,"criteria":"cpe:2.3:o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:*","matchCriteriaId":"10082781-B93E-4B84-94F2-FA9749B4D92B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3618","Ordinal":"1","Title":"CVE-2008-3618","CVE":"CVE-2008-3618","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3618","Ordinal":"1","NoteData":"The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their own home directories are shared for their own use, which might allow attackers to leverage other vulnerabilities and access files for which sharing was unintended.","Type":"Description","Title":"CVE-2008-3618"},{"CveYear":"2008","CveId":"3618","Ordinal":"2","NoteData":"2008-09-16","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3618","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}