CVE

Id
38378  
CVE No.
CVE-2009-0943  
Status
Candidate  
Description
Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.  
Phase
Assigned (20090318)  
Votes
None (candidate not yet proposed)  
Comments