← Vulnerability feed

Vulnerability record · CVE-2008-2540 · published 3 June 2008

CVE-2008-2540: Apple safari permissions and access controls vulnerability

Apple · Safari

Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.

9.3 CVSS 2.0 High EPSS 8.3% · top 5.3% CWE-264 · Permissions and access controls
9.3CVSS 2.0 base score
8.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
42References
16 Jun 2026Last modified by NVD

Description

Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://aviv.raffon.net/2008/05/31/SafariPwnsInternetExplorer.aspx Third Party Advisory
http://blogs.zdnet.com/security/?p=1230 Third Party Advisory
http://lists.apple.com/archives/security-announce/2008//Jun/msg00001.html Mailing ListVendor Advisory
http://secunia.com/advisories/30467 Third Party Advisory
http://securitytracker.com/id?1020150 Third Party AdvisoryVDB Entry
http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm Third Party Advisory
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=871138 Third Party Advisory
http://www.dhanjani.com/archives/2008/05/safari_carpet_bomb.html Broken Link
http://www.microsoft.com/technet/security/advisory/953818.mspx MitigationPatchVendor Advisory
http://www.securityfocus.com/bid/29445 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1022047 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA09-104A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2008/1706 Broken Link
http://www.vupen.com/english/advisories/2009/1028 Broken Link
http://www.vupen.com/english/advisories/2009/1029 Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-014
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-015
https://exchange.xforce.ibmcloud.com/vulnerabilities/42765 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5782 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6108 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8509 Third Party Advisory
http://aviv.raffon.net/2008/05/31/SafariPwnsInternetExplorer.aspx Third Party Advisory
http://blogs.zdnet.com/security/?p=1230 Third Party Advisory
http://lists.apple.com/archives/security-announce/2008//Jun/msg00001.html Mailing ListVendor Advisory
http://secunia.com/advisories/30467 Third Party Advisory
http://securitytracker.com/id?1020150 Third Party AdvisoryVDB Entry
http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm Third Party Advisory
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=871138 Third Party Advisory
http://www.dhanjani.com/archives/2008/05/safari_carpet_bomb.html Broken Link
http://www.microsoft.com/technet/security/advisory/953818.mspx MitigationPatchVendor Advisory
http://www.securityfocus.com/bid/29445 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1022047 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA09-104A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2008/1706 Broken Link
http://www.vupen.com/english/advisories/2009/1028 Broken Link
http://www.vupen.com/english/advisories/2009/1029 Broken Link
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-014
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-015
https://exchange.xforce.ibmcloud.com/vulnerabilities/42765 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5782 Third Party Advisory

Track CVE-2008-2540 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed8.8CVE-2025-43529Apple WebKit use-after-free allows code execution via crafted web contentA use-after-free flaw in Apple's WebKit engine was fixed through improved memory management across Safari, iOS, iPadOS, macOS, tvOS, visionOS and wat…KEVEPSS 8.8%analysed8.8CVE-2025-14174Google Chrome ANGLE out-of-bounds memory access on MacChrome on macOS before 143.0.7499.110 contains an out-of-bounds memory access in the ANGLE graphics layer, classified as an out-of-bounds write (CWE-…KEVEPSS 22%analysed8.8CVE-2023-43000Apple WebKit use-after-free via malicious web contentA use-after-free flaw in Apple's WebKit engine was fixed by improved memory management in macOS Ventura 13.5, iOS/iPadOS 16.6, Safari 16.6, and iOS/i…KEVEPSS 3.9%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2025-6558Chrome ANGLE and GPU input validation flaw enables sandbox escapeGoogle Chrome before 138.0.7204.157 fails to properly validate untrusted input in ANGLE and the GPU component, allowing a crafted HTML page to trigge…KEVEPSS 9.6%analysed8.8CVE-2024-44308Apple WebKit code execution via malicious web contentApple fixed a WebKit flaw with improved checks across Safari, iOS, iPadOS, macOS and visionOS. Processing maliciously crafted web content can lead to…KEVEPSS 10%analysed8.8CVE-2024-23222Apple WebKit type confusion allows code execution via crafted web contentA type confusion flaw in Apple's WebKit engine was addressed with improved checks. Processing maliciously crafted web content can lead to arbitrary c…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2008-2540), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.