CVE-2008-1036

EUVD-2008-1047
The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character encodings, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
applemac_os_x
10.4.11
applemac_os_x
10.5
applemac_os_x
10.5.1
applemac_os_x
10.5.2
applemac_os_x_server
10.4.11
applemac_os_x_server
10.5
applemac_os_x_server
10.5.1
applemac_os_x_server
10.5.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
icu
bookworm
72.1-3
fixed
bullseye
67.1-7
fixed
sid
72.1-5
fixed
trixie
72.1-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
icu
dapper
Fixed 3.4.1a-1ubuntu1.6.06.2
released
gutsy
Fixed 3.6-3ubuntu0.2
released
hardy
Fixed 3.8-6ubuntu0.1
released
intrepid
Fixed 3.8.1-2ubuntu0.1
released