CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
91.4%
Apple Safari before 4.0 does not prevent calls to the open-help-anchor URL handler by web sites, which allows remote attackers to open arbitrary local help files, and execute arbitrary code or obtain sensitive information, via a crafted call.
Vendor | Product | Version | CPE |
---|---|---|---|
apple | safari | * | cpe:2.3:a:apple:safari:*:-:mac:*:*:*:*:* |
apple | safari | 0.8 | cpe:2.3:a:apple:safari:0.8:-:mac:*:*:*:*:* |
apple | safari | 0.9 | cpe:2.3:a:apple:safari:0.9:-:mac:*:*:*:*:* |
apple | safari | 1.0 | cpe:2.3:a:apple:safari:1.0:-:mac:*:*:*:*:* |
apple | safari | 1.0.3 | cpe:2.3:a:apple:safari:1.0.3:-:mac:*:*:*:*:* |
apple | safari | 1.1 | cpe:2.3:a:apple:safari:1.1:-:mac:*:*:*:*:* |
apple | safari | 1.2 | cpe:2.3:a:apple:safari:1.2:-:mac:*:*:*:*:* |
apple | safari | 1.3 | cpe:2.3:a:apple:safari:1.3:-:mac:*:*:*:*:* |
apple | safari | 1.3.1 | cpe:2.3:a:apple:safari:1.3.1:-:mac:*:*:*:*:* |
apple | safari | 1.3.2 | cpe:2.3:a:apple:safari:1.3.2:-:mac:*:*:*:*:* |