Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2008-2540 Details

Description

Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://aviv.raffon.net/2008/05/31/SafariPwnsInternetExplorer.aspx CVEThird Party Advisory
http://blogs.zdnet.com/security/?p=1230 CVEThird Party Advisory
http://lists.apple.com/archives/security-announce/2008//Jun/msg00001.html CVEMailing ListVendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-014 CVE
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-015 CVE

see all 42 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-264Permissions, Privileges, and Access Controls[email protected]

Affected Products

ProductVersions

Change History

16 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2008-2540
NVD Published Date:
Jun 3, 2008
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2008-2540 Details - Not Deferred