Vulnerability CVE-2005-1331


Published: 2005-05-04   Modified: 2012-02-12

Description:
The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control characters, and homographs.

CVSS2 => (AV:N/AC:H/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.1/10
6.4/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Apple -> Applescript 
Apple -> Mac os x 
Apple -> Mac os x server 

 References:
http://www.securityfocus.com/bid/13480
http://secunia.com/advisories/15227
http://lists.apple.com/archives/security-announce/2005/May/msg00001.html
http://www.vupen.com/english/advisories/2005/0455
http://remahl.se/david/vuln/010/

Copyright 2021, cxsecurity.com

 

Back to Top