Unrated severityNVD Advisory· Published Sep 11, 2008· Updated Apr 23, 2026
CVE-2008-3632
CVE-2008-3632
Description
Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a web page with crafted Cascading Style Sheets (CSS) import statements.
Affected products
16cpe:2.3:h:apple:iphone:1.1:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:h:apple:iphone:1.1:*:*:*:*:*:*:*
- cpe:2.3:h:apple:iphone:1.1.3:*:*:*:*:*:*:*
- cpe:2.3:h:apple:iphone:1.1.4:*:*:*:*:*:*:*
- cpe:2.3:h:apple:iphone:2.0:*:*:*:*:*:*:*
- cpe:2.3:h:apple:iphone:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:h:apple:iphone:2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:apple:ipod_touch:1.1:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:h:apple:ipod_touch:1.1:*:*:*:*:*:*:*
- cpe:2.3:h:apple:ipod_touch:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:h:apple:ipod_touch:1.1.2:*:*:*:*:*:*:*
- cpe:2.3:h:apple:ipod_touch:1.1.3:*:*:*:*:*:*:*
- cpe:2.3:h:apple:ipod_touch:1.1.4:*:*:*:*:*:*:*
- cpe:2.3:h:apple:ipod_touch:2.0:*:*:*:*:*:*:*
- cpe:2.3:h:apple:ipod_touch:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:h:apple:ipod_touch:2.0.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:iphone_os:1.1.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:iphone_os:1.1.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
18- lists.apple.com/archives/security-announce//2008/Sep/msg00003.htmlnvdPatchVendor Advisory
- lists.apple.com/archives/security-announce//2008/Sep/msg00004.htmlnvdPatchVendor Advisory
- lists.apple.com/archives/security-announce/2009/jun/msg00002.htmlnvdPatchVendor Advisory
- support.apple.com/kb/HT3026nvdPatchVendor Advisory
- support.apple.com/kb/HT3129nvdPatchVendor Advisory
- support.apple.com/kb/HT3613nvdPatchVendor Advisory
- www.securityfocus.com/bid/31092nvdPatch
- www.vupen.com/english/advisories/2009/1522nvdPatchVendor Advisory
- secunia.com/advisories/31823nvdVendor Advisory
- secunia.com/advisories/31900nvdVendor Advisory
- secunia.com/advisories/32099nvdVendor Advisory
- secunia.com/advisories/35379nvdVendor Advisory
- www.vupen.com/english/advisories/2008/2525nvdVendor Advisory
- www.vupen.com/english/advisories/2008/2558nvdVendor Advisory
- lists.opensuse.org/opensuse-security-announce/2008-09/msg00005.htmlnvd
- secunia.com/advisories/32860nvd
- www.securitytracker.com/idnvd
- www.ubuntu.com/usn/USN-676-1nvd
News mentions
0No linked articles in our index yet.