VulnerabilityModified
CVE-2010-1805
Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 on Windows allows local users to gain privileges via a Trojan horse explorer.exe (aka Windows Explorer) program in a directory containing a file that had been…
MEDIUM 6.9EPSS 0.30%
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 on Windows allows local users to gain privileges via a Trojan horse explorer.exe (aka Windows Explorer) program in a directory containing a file that had been downloaded by Safari.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.30% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- apple/safari
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2010//Sep/msg00001.htmlVendor Advisory
- http://support.apple.com/kb/HT4333Vendor Advisory
- http://www.securityfocus.com/bid/43048Patch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11956
- http://lists.apple.com/archives/security-announce/2010//Sep/msg00001.htmlVendor Advisory
- http://support.apple.com/kb/HT4333Vendor Advisory
- http://www.securityfocus.com/bid/43048Patch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11956
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.