Vulnerability Name: | CVE-2004-0486 (CCN-43222) | ||||||||
Assigned: | 2004-05-15 | ||||||||
Published: | 2004-05-15 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C) 5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Sat May 15 2004 - 17:00:08 CDT Vuln. MacOSX/Safari: Remote help-call, execute scripts Source: FULLDISC Type: UNKNOWN 20040516 Vuln. MacOSX/Safari: Remote help-call, execute scripts Source: MITRE Type: CNA CVE-2004-0486 Source: APPLE Type: UNKNOWN APPLE-SA-2004-05-21 Source: CCN Type: SA11622 Mac OS X URI Handler Arbitrary Code Execution Source: SECUNIA Type: Patch, Vendor Advisory 11622 Source: CCN Type: SECTRACK ID: 1010167 Apple Safari `runscript` Function Lets Remote Users Execute Code Source: SECTRACK Type: UNKNOWN 1010167 Source: CCN Type: Apple Web site Apple - Mac OS X Source: MISC Type: Vendor Advisory http://www.fundisom.com/owned/warning Source: CCN Type: US-CERT VU#578798 Apple Mac OS X help system may interpret inappropriate local script files Source: CERT-VN Type: Patch, Third Party Advisory, US Government Resource VU#578798 Source: OSVDB Type: UNKNOWN 6184 Source: CCN Type: OSVDB ID: 6184 Apple Mac OS X Help URI Script Execution Source: BID Type: Exploit, Patch, Vendor Advisory 10356 Source: CCN Type: BID-10356 Apple Mac OS X Help Protocol Remote Code Execution Vulnerability Source: XF Type: UNKNOWN macos-runscript-code-execution(16166) Source: XF Type: UNKNOWN macos-helpviewer-scripts-code-execution(43222) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |