Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xjp5-gg6j-cwrg

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari.

The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari.

EPSS

Процентиль: 62%
0.00421
Низкий

Связанные уязвимости

nvd
больше 19 лет назад

The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari.

EPSS

Процентиль: 62%
0.00421
Низкий