VDB
CVE-2004-0486
CVE-2004-0486
PUBLISHED
CVSS 7.599999904632568 HIGH
HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.
EPSS 9.66% · 95.3th percentile
Risk Scores
CVSS 2.0
7.599999904632568
EPSS Score
9.66%
95.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | mac_os_x | 10.3.3, 10.3, 10.3.1 |
| apple | mac_os_x_server | 10.3.3, 10.3, 10.3.1 |
| n/a | n/a | * |
Timeline
- May 28, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 5, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Nov 1, 2023 EPSS Score
References
- 10356 vdb
- 6184 vdb
- 20040516 Vuln. MacOSX/Safari: Remote help-call, execute scripts mailing-list
- http://lists.apple.com/mhonarc/security-announce/msg00053.html technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16166 technical
- http://secunia.com/advisories/11622/ patch
- http://securitytracker.com/id?1010167 technical
- http://www.kb.cert.org/vuls/id/578798 patch
- https://nvd.nist.gov/vuln/detail/CVE-2004-0486 advisory
- http://secunia.com/advisories/11622 url
- http://www.fundisom.com/owned/warning url