Unrated severityNVD Advisory· Published Jun 2, 2008· Updated Apr 23, 2026
CVE-2008-1580
CVE-2008-1580
Description
CFNetwork in Safari in Apple Mac OS X before 10.5.3 automatically sends an SSL client certificate in response to a web server's certificate request, which allows remote web sites to obtain sensitive information (Subject data) from personally identifiable certificates, and use arbitrary certificates to track user activities across domains, a related issue to CVE-2007-4879.
Affected products
1- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- lists.apple.com/archives/security-announce/2008//May/msg00001.htmlnvdPatch
- www.us-cert.gov/cas/techalerts/TA08-150A.htmlnvdPatchUS Government Resource
- secunia.com/advisories/30430nvdVendor Advisory
- securitytracker.com/idnvd
- www.securityfocus.com/bid/29412nvd
- www.securityfocus.com/bid/29493nvd
- www.vupen.com/english/advisories/2008/1697nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/42708nvd
News mentions
0No linked articles in our index yet.