6.8
CVSSv2

CVE-2008-2309

Published: 01/07/2008 Updated: 08/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X prior to 10.5.4 allows user-assisted remote malicious users to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.4.5

apple mac os x 10.4.6

apple mac os x 10.5.3

apple mac os x server 10.4.1

apple mac os x 10.4.1

apple mac os x 10.4.10

apple mac os x 10.4.7

apple mac os x 10.4.8

apple mac os x server 10.4.10

apple mac os x server 10.4.11

apple mac os x server 10.4.9

apple mac os x server 10.5

apple mac os x server 10.4.7

apple mac os x server 10.4.8

apple mac os x 10.4.11

apple mac os x 10.4.2

apple mac os x 10.4.9

apple mac os x 10.5

apple mac os x server 10.4.2

apple mac os x server 10.4.3

apple mac os x server 10.5.1

apple mac os x server 10.5.2

apple mac os x 10.4.3

apple mac os x 10.4.4

apple mac os x 10.5.1

apple mac os x 10.5.2

apple mac os x server 10.4.4

apple mac os x server 10.4.5

apple mac os x server 10.4.6

apple mac os x server 10.5.3