Lucene search

K
cveAppleCVE-2013-5135
HistoryOct 24, 2013 - 3:48 a.m.

CVE-2013-5135

2013-10-2403:48:48
CWE-134
apple
web.nvd.nist.gov
28
cve-2013-5135
format string vulnerability
screen sharing server
apple
mac os x
remote code execution
vnc username

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.017

Percentile

88.0%

Format string vulnerability in Screen Sharing Server in Apple Mac OS X before 10.9 and Apple Remote Desktop before 3.5.4 allows remote attackers to execute arbitrary code via format string specifiers in a VNC username.

Affected configurations

Nvd
Node
appleapple_remote_desktopRange3.5.3
OR
appleapple_remote_desktopMatch3.0.0
OR
appleapple_remote_desktopMatch3.1
OR
appleapple_remote_desktopMatch3.2
OR
appleapple_remote_desktopMatch3.2.1
OR
appleapple_remote_desktopMatch3.2.2
OR
appleapple_remote_desktopMatch3.3
OR
appleapple_remote_desktopMatch3.3.1
OR
appleapple_remote_desktopMatch3.3.2
OR
appleapple_remote_desktopMatch3.4
OR
appleapple_remote_desktopMatch3.5
OR
appleapple_remote_desktopMatch3.5.1
OR
appleapple_remote_desktopMatch3.5.2
Node
applemac_os_xRange10.8.5supplemental_update
OR
applemac_os_xMatch10.8.0
OR
applemac_os_xMatch10.8.1
OR
applemac_os_xMatch10.8.2
OR
applemac_os_xMatch10.8.3
OR
applemac_os_xMatch10.8.4
OR
applemac_os_xMatch10.8.5
VendorProductVersionCPE
appleapple_remote_desktop*cpe:2.3:a:apple:apple_remote_desktop:*:*:*:*:*:*:*:*
appleapple_remote_desktop3.0.0cpe:2.3:a:apple:apple_remote_desktop:3.0.0:*:*:*:*:*:*:*
appleapple_remote_desktop3.1cpe:2.3:a:apple:apple_remote_desktop:3.1:*:*:*:*:*:*:*
appleapple_remote_desktop3.2cpe:2.3:a:apple:apple_remote_desktop:3.2:*:*:*:*:*:*:*
appleapple_remote_desktop3.2.1cpe:2.3:a:apple:apple_remote_desktop:3.2.1:*:*:*:*:*:*:*
appleapple_remote_desktop3.2.2cpe:2.3:a:apple:apple_remote_desktop:3.2.2:*:*:*:*:*:*:*
appleapple_remote_desktop3.3cpe:2.3:a:apple:apple_remote_desktop:3.3:*:*:*:*:*:*:*
appleapple_remote_desktop3.3.1cpe:2.3:a:apple:apple_remote_desktop:3.3.1:*:*:*:*:*:*:*
appleapple_remote_desktop3.3.2cpe:2.3:a:apple:apple_remote_desktop:3.3.2:*:*:*:*:*:*:*
appleapple_remote_desktop3.4cpe:2.3:a:apple:apple_remote_desktop:3.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.017

Percentile

88.0%