CVE-2005-1933

Mac OS X Tiger 10.4 - Arbitrary Command Execution via Widget Bundle Identifier Override

Title source: llm
STIX 2.1

Description

Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/983429
Exploit, Vendor Advisory x_refsource_misc
http://www1.cs.columbia.edu/~aaron/files/widgets/

Scores

EPSS 0.0183
EPSS Percentile 76.7%

Details

Status published
Products (1)
apple/mac_os_x 10.4
Published Jun 13, 2005
Tracked Since Feb 18, 2026