{"api_version":"1","generated_at":"2026-07-23T06:11:02+00:00","cve":"CVE-2008-3630","urls":{"html":"https://cve.report/CVE-2008-3630","api":"https://cve.report/api/cve/CVE-2008-3630.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3630","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3630"},"summary":{"title":"CVE-2008-3630","description":"mDNSResponder in Apple Bonjour for Windows before 1.0.5, when an application uses the Bonjour API for unicast DNS, does not choose random values for transaction IDs or source ports in DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-09-11 01:13:09","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:P","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2008/2524","name":"http://www.vupen.com/english/advisories/2008/2524","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00002.html","name":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"APPLE-SA-2009-09-09 Bonjour for Windows 1.0.5","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT2990","name":"http://support.apple.com/kb/HT2990","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About the security content of Bonjour for Windows 1.0.5","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/31093","name":"http://www.securityfocus.com/bid/31093","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple Bonjour for Windows mDNSResponder Remote Forged DNS Response Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/31822","name":"http://secunia.com/advisories/31822","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple Bonjour for Windows mDNSResponder Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1020844","name":"http://www.securitytracker.com/id?1020844","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apple Bonjour for Windows DNS Query Port Entropy Weakness Lets Remote Users Spoof the System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3630","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3630","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3630","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apple","cpe5":"bonjour","cpe6":"1.0.4","cpe7":"unknown","cpe8":"windows","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3630","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows-nt","cpe6":"xp","cpe7":"sp3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3630","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2000","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3630","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3630","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_vista","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3630","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"-","cpe7":"sp2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:45:18.954Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"31822","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31822"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT2990"},{"name":"APPLE-SA-2009-09-09","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00002.html"},{"name":"1020844","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1020844"},{"name":"ADV-2008-2524","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/2524"},{"name":"31093","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31093"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-09-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"mDNSResponder in Apple Bonjour for Windows before 1.0.5, when an application uses the Bonjour API for unicast DNS, does not choose random values for transaction IDs or source ports in DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-09-24T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"31822","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31822"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT2990"},{"name":"APPLE-SA-2009-09-09","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00002.html"},{"name":"1020844","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1020844"},{"name":"ADV-2008-2524","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/2524"},{"name":"31093","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31093"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3630","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"mDNSResponder in Apple Bonjour for Windows before 1.0.5, when an application uses the Bonjour API for unicast DNS, does not choose random values for transaction IDs or source ports in DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"31822","refsource":"SECUNIA","url":"http://secunia.com/advisories/31822"},{"name":"http://support.apple.com/kb/HT2990","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT2990"},{"name":"APPLE-SA-2009-09-09","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce//2008/Sep/msg00002.html"},{"name":"1020844","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1020844"},{"name":"ADV-2008-2524","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/2524"},{"name":"31093","refsource":"BID","url":"http://www.securityfocus.com/bid/31093"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3630","datePublished":"2008-09-10T16:00:00.000Z","dateReserved":"2008-08-12T00:00:00.000Z","dateUpdated":"2024-08-07T09:45:18.954Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-09-11 01:13:09","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:P","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apple:bonjour:1.0.4:unknown:windows:*:*:*:*:*","matchCriteriaId":"1ACABF55-DE3F-463A-A469-A76589C3AAB9"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows-nt:xp:sp3:*:*:*:*:*:*","matchCriteriaId":"73AED29E-B778-4186-8968-EB608E34E540"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*","matchCriteriaId":"685F1981-EA61-4A00-89F8-A748A88962F8"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:-:*:*:*:*:*:*:*","matchCriteriaId":"EAA86830-BEA8-4943-83EA-C267FA534223"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*","matchCriteriaId":"7CAEEA81-5037-4B68-98D9-83AAEBC98E20"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:*:*:*:*","matchCriteriaId":"34DF3B5E-F17F-49B4-9DC8-06749F3C9CC3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3630","Ordinal":"1","Title":"CVE-2008-3630","CVE":"CVE-2008-3630","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3630","Ordinal":"1","NoteData":"mDNSResponder in Apple Bonjour for Windows before 1.0.5, when an application uses the Bonjour API for unicast DNS, does not choose random values for transaction IDs or source ports in DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.","Type":"Description","Title":"CVE-2008-3630"},{"CveYear":"2008","CveId":"3630","Ordinal":"2","NoteData":"2008-09-10","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3630","Ordinal":"3","NoteData":"2008-09-24","Type":"Other","Title":"Modified"}]}}}