SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-0063

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of…

MEDIUM 6.8EPSS 1.57%

Does this matter?

Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.

Description

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari, as demonstrated by the values for the (1) .ibplugin and (2) .url extensions.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
1.57% probability · 74th percentile
CISA KEV
Not listed
Affected
apple/mac os x · apple/mac os x server
Source
product-security@apple.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.