VulnerabilityModified
CVE-2012-3718
Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 allows local users to read passwords entered into Login Window (aka LoginWindow) or Screen Saver Unlock by installing an input method that intercepts keystrokes.
LOW 2.1EPSS 0.31%
Does this matter?
Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.
Description
Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 allows local users to read passwords entered into Login Window (aka LoginWindow) or Screen Saver Unlock by installing an input method that intercepts keystrokes.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.31% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/mac os x · apple/mac os x server
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.htmlVendor Advisory
- http://osvdb.org/85647
- http://support.apple.com/kb/HT5501Vendor Advisory
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.htmlVendor Advisory
- http://osvdb.org/85647
- http://support.apple.com/kb/HT5501Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.