Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3wf3-2hqv-7qjg

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.

Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.

EPSS

Процентиль: 85%
0.02541
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 16 лет назад

Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.

EPSS

Процентиль: 85%
0.02541
Низкий

Дефекты

CWE-20