Unrated severityNVD Advisory· Published Jun 2, 2008· Updated Apr 23, 2026
CVE-2008-1030
CVE-2008-1030
Description
Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial of service (crash) via an invalid length argument, which triggers a heap-based buffer overflow.
Affected products
8cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- secunia.com/advisories/30430nvdVendor Advisory
- www.vupen.com/english/advisories/2008/1697nvdVendor Advisory
- www.us-cert.gov/cas/techalerts/TA08-150A.htmlnvdUS Government Resource
- lists.apple.com/archives/security-announce/2008//May/msg00001.htmlnvd
- securitytracker.com/idnvd
- www.securityfocus.com/bid/29412nvd
- www.securityfocus.com/bid/29491nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/42709nvd
News mentions
0No linked articles in our index yet.