The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control characters, and homographs.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
20 Nov 2024, 23:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.apple.com/archives/security-announce/2005/May/msg00001.html - Patch | |
References | () http://remahl.se/david/vuln/010/ - Exploit | |
References | () http://secunia.com/advisories/15227 - Patch | |
References | () http://www.securityfocus.com/bid/13480 - Patch | |
References | () http://www.vupen.com/english/advisories/2005/0455 - |
Information
Published : 2005-05-04 04:00
Updated : 2024-11-20 23:57
NVD link : CVE-2005-1331
Mitre link : CVE-2005-1331
CVE.ORG link : CVE-2005-1331
JSON object : View
Products Affected
apple
- mac_os_x
- applescript
- mac_os_x_server
CWE