Lucene search

K
cveAppleCVE-2010-1805
HistorySep 10, 2010 - 7:00 p.m.

CVE-2010-1805

2010-09-1019:00:01
CWE-264
apple
web.nvd.nist.gov
27
cve-2010-1805
untrusted search path vulnerability
apple safari
windows
privilege escalation
trojan horse
explorer.exe

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

5.1%

Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 on Windows allows local users to gain privileges via a Trojan horse explorer.exe (aka Windows Explorer) program in a directory containing a file that had been downloaded by Safari.

Affected configurations

Nvd
Node
applesafariMatch4.0
OR
applesafariMatch4.0.0b
OR
applesafariMatch4.0.1
OR
applesafariMatch4.0.2
OR
applesafariMatch4.0.3
OR
applesafariMatch4.0.4
OR
applesafariMatch4.0.5
OR
applesafariMatch4.1
OR
applesafariMatch5.0
OR
applesafariMatch5.0.1
AND
microsoftwindows
VendorProductVersionCPE
applesafari5.0cpe:/a:apple:safari:5.0:::
applesafari4.0.4cpe:/a:apple:safari:4.0.4:::
applesafari4.1cpe:/a:apple:safari:4.1:::
applesafari5.0.1cpe:/a:apple:safari:5.0.1:::
applesafari4.0.3cpe:/a:apple:safari:4.0.3:::
applesafari4.0.2cpe:/a:apple:safari:4.0.2:::
applesafari4.0.1cpe:/a:apple:safari:4.0.1:::
applesafari4.0.0bcpe:/a:apple:safari:4.0.0b:::
applesafari4.0cpe:/a:apple:safari:4.0:::
applesafari4.0.5cpe:/a:apple:safari:4.0.5:::

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.1

Confidence

Low

EPSS

0

Percentile

5.1%