CVE-2013-0967

CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which allows remote attackers to bypass a Java plug-in disabled setting, and trigger the launch of Java Web Start applications, via a crafted web site.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:mac_os_x:10.7.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.7.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.7.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.7.3:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.7.4:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.7.5:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.7.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.7.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.7.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.7.3:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:apple:mac_os_x:10.8.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.8.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.8.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-03-15 20:55

Updated : 2023-12-10 11:16


NVD link : CVE-2013-0967

Mitre link : CVE-2013-0967

CVE.ORG link : CVE-2013-0967


JSON object : View

Products Affected

apple

  • mac_os_x
  • mac_os_x_server