CVE-2005-2516

Safari in Mac OS X 10.3.9 and 10.4.2 - Remote Code Execution via RTF URL Handling

Title source: llm
STIX 2.1

Description

Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands.

References (4)

Core 4
Core References
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/709220
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA05-229A.html
Patch, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html
Patch, Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html

Scores

EPSS 0.0477
EPSS Percentile 91.0%

Details

Status published
Products (3)
apple/mac_os_x 10.3.9
apple/mac_os_x 10.4.2
apple/safari
Published Aug 19, 2005
Tracked Since Feb 18, 2026