CVE-2004-1021

iCal - Unauthenticated Arbitrary Program Execution via Calendar Alarm

Title source: llm
STIX 2.1

Description

iCal before 1.5.4 on Mac OS X 10.2.3, and other later versions, does not alert the user when handling calendars that use alarms, which allows attackers to execute programs and send e-mail via alarms.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18209
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce//2004/Nov/msg00000.html

Scores

EPSS 0.0108
EPSS Percentile 61.8%

Details

Status published
Products (1)
apple/ical 1.5.3
Published Mar 01, 2005
Tracked Since Feb 18, 2026