9.3
CVSSv2

CVE-2007-6165

Published: 29/11/2007 Updated: 06/10/2011
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote malicious users to execute arbitrary code via an AppleDouble attachment containing an apparently-safe file type and script in a resource fork, which does not warn the user that a separate program is going to be executed. NOTE: this is a regression error related to CVE-2006-0395.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.5

Exploits

## # $Id: mailapp_image_execrb 10397 2010-09-20 15:59:46Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' cl ...
source: wwwsecurityfocuscom/bid/26510/info Apple Mac OS X is prone to a vulnerability that can allow arbitrary code to run This issue affects the Mail application when handling email attachments Attackers can exploit this issue to execute arbitrary code in the context of the user running the application This will compromise the applic ...