Saffron

Saffron (also known as JailbreakMe 3.0) is a userland untethered jailbreak from comex that utilizes JailbreakMe.com, yet again. It was the first jailbreak made available to the public for the iPad 2 running iOS 4.3.3. In 2011, comex began to put up teasers on JailbreakMe. In early 2011, someone Googled comex's other site and found a prerelease version of "Saffron," the third incarnation of JailbreakMe. Word about this "leak" inevitably spread. On 2011, "Saffron" made its official debut on JailbreakMe. An incomplete prerelease version was leaked on 2011, after it was discovered on comex's server.

This jailbreak was patched on 2011 with the releases of iOS 4.2.9 (iPhone 4 (iPhone3,3)) and 4.3.4 (all other devices).

Exploits Used

 * T1 Font Integer Overflow
 * IOMobileFrameBuffer Privilege Escalation Exploit

Domain owner problem
On 2011, MuscleNerd announced that the domain was sold and that the new owner was unknown, so that there is a big danger of the site hosting malware. It turned out that the new owner was friendly and sold it the next day to Saurik who hosted the site anyway. Problem solved.

Certificate problem
Starting early 2015, the domain started to display a blank homepage. In addition, JailbreakMe began to redirect traffic to HTTPS; however, the TLS certificate it was using was invalid. Turns out comex moved the files to his personal domain.