Description
The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control characters, and homographs.
References (5)
Core 5
Core References
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/13480
Patch third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/15227
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2005/0455
Exploit x_refsource_misc
http://remahl.se/david/vuln/010/
Patch vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2005/May/msg00001.html
Scores
EPSS
0.0232
EPSS Percentile
81.8%
Details
Status
published
Products (21)
apple/applescript
2.0.0
apple/mac_os_x
10.3
apple/mac_os_x
10.3.1
apple/mac_os_x
10.3.2
apple/mac_os_x
10.3.3
apple/mac_os_x
10.3.4
apple/mac_os_x
10.3.5
apple/mac_os_x
10.3.6
apple/mac_os_x
10.3.7
apple/mac_os_x
10.3.8
... and 11 more
Published
May 04, 2005
Tracked Since
Feb 18, 2026