7.5

CVE-2013-5135

Format string vulnerability in Screen Sharing Server in Apple Mac OS X before 10.9 and Apple Remote Desktop before 3.5.4 allows remote attackers to execute arbitrary code via format string specifiers in a VNC username.

Data is provided by the National Vulnerability Database (NVD)
AppleApple Remote Desktop Version <= 3.5.3
AppleApple Remote Desktop Version3.0.0
AppleApple Remote Desktop Version3.1
AppleApple Remote Desktop Version3.2
AppleApple Remote Desktop Version3.2.1
AppleApple Remote Desktop Version3.2.2
AppleApple Remote Desktop Version3.3
AppleApple Remote Desktop Version3.3.1
AppleApple Remote Desktop Version3.3.2
AppleApple Remote Desktop Version3.4
AppleApple Remote Desktop Version3.5
AppleApple Remote Desktop Version3.5.1
AppleApple Remote Desktop Version3.5.2
ApplemacOS X Updatesupplemental_update Version <= 10.8.5
ApplemacOS X Version10.8.0
ApplemacOS X Version10.8.1
ApplemacOS X Version10.8.2
ApplemacOS X Version10.8.3
ApplemacOS X Version10.8.4
ApplemacOS X Version10.8.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.06% 0.862
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-134 Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.