HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes...
High severity
Unreviewed
Published
Apr 29, 2022
to the GitHub Advisory Database
•
Updated Apr 3, 2025
Description
Published by the National Vulnerability Database
Jul 7, 2004
Published to the GitHub Advisory Database
Apr 29, 2022
Last updated
Apr 3, 2025
HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.
References