VDB
CVE-2005-2757
CVE-2005-2757
PUBLISHED
CVSS 7.5 HIGH
Heap-based buffer overflow in CoreFoundation in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to execute arbitrary code via unknown attack vectors involving "validation of URLs."
EPSS 3.53% · 88.1th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
3.53%
88.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | mac_os_x | 10.3.1, 10.3, 10.3.9 |
| n/a | n/a | n/a |
| apple | mac_os_x_server | 10.3.1, 10.3.8, 10.4.3 |
Timeline
- Dec 1, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- 1015285 vdb
- 17813 third-party-advisory
- APPLE-SA-2005-11-29 vendor-advisory
- macos-corefoundation-url-bo(23329) vdb
- http://www.osvdb.org/21271 technical
- http://www.securityfocus.com/bid/15647 patch
- http://www.vupen.com/english/advisories/2005/2659 technical
- https://nvd.nist.gov/vuln/detail/CVE-2005-2757 advisory