Lucene search

K
cveMitreCVE-2008-1032
HistoryJun 02, 2008 - 9:30 p.m.

CVE-2008-1032

2008-06-0221:30:00
mitre
web.nvd.nist.gov
40
cve-2008-1032
incomplete blacklist vulnerability
coretypes
apple
mac os x
code execution
user-assisted remote attackers
automator
help
safari
terminal
download validation
quarantine
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.037

Percentile

91.9%

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1) Automator, (2) Help, (3) Safari, or (4) Terminal content type for a downloadable object, which does not trigger a “potentially unsafe” warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5.

Affected configurations

Nvd
Node
applemac_os_xMatch10.4.11
OR
applemac_os_xMatch10.5
OR
applemac_os_xMatch10.5.1
OR
applemac_os_xMatch10.5.2
OR
applemac_os_x_serverMatch10.4.11
OR
applemac_os_x_serverMatch10.5
OR
applemac_os_x_serverMatch10.5.1
OR
applemac_os_x_serverMatch10.5.2
VendorProductVersionCPE
applemac_os_x_server10.4.11cpe:/o:apple:mac_os_x_server:10.4.11:::
applemac_os_x10.5.2cpe:/o:apple:mac_os_x:10.5.2:::
applemac_os_x_server10.5.1cpe:/o:apple:mac_os_x_server:10.5.1:::
applemac_os_x10.5.1cpe:/o:apple:mac_os_x:10.5.1:::
applemac_os_x_server10.5cpe:/o:apple:mac_os_x_server:10.5:::
applemac_os_x10.5cpe:/o:apple:mac_os_x:10.5:::
applemac_os_x_server10.5.2cpe:/o:apple:mac_os_x_server:10.5.2:::
applemac_os_x10.4.11cpe:/o:apple:mac_os_x:10.4.11:::

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.037

Percentile

91.9%