CVE-2005-1331

AppleScript Editor <10.3.9 - Code Injection

Title source: llm
STIX 2.1

Description

The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control characters, and homographs.

References (5)

Core 5
Core References
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13480
Patch third-party-advisory x_refsource_secunia
http://secunia.com/advisories/15227
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/0455
Exploit x_refsource_misc
http://remahl.se/david/vuln/010/

Scores

EPSS 0.0232
EPSS Percentile 81.8%

Details

Status published
Products (21)
apple/applescript 2.0.0
apple/mac_os_x 10.3
apple/mac_os_x 10.3.1
apple/mac_os_x 10.3.2
apple/mac_os_x 10.3.3
apple/mac_os_x 10.3.4
apple/mac_os_x 10.3.5
apple/mac_os_x 10.3.6
apple/mac_os_x 10.3.7
apple/mac_os_x 10.3.8
... and 11 more
Published May 04, 2005
Tracked Since Feb 18, 2026