Sploitus

CVE-2009-1727

1 known exploit for CVE-2009-1727

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari.

Affected products
Macos X, Safari
Apple Mac Os X
= 10.5.6, 10.5, 10.5.0, 10.5.1, 10.5.2, 10.5.3, 10.5.4, 10.5.5, 10.5.7
Apple Mac Os X Server
= 10.5, 10.5.0, 10.5.1, 10.5.2, 10.5.3, 10.5.4, 10.5.5, 10.5.6, 10.5.7
CVSS 2.0
6.8 MEDIUM
EPSS
2.7% (84th percentile)
NVD status
Modified
Published
2009-08-06
CVE-2009-1727 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2009-1727

Proof-of-concept code and exploit modules indexed by Sploitus