Arbitrary Command Execution via Dashboard Widget Override in Apple Mac OS X Tiger 10.4

Arbitrary Command Execution via Dashboard Widget Override in Apple Mac OS X Tiger 10.4

CVE-2005-1933 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.

Learn more about our User Device Pen Test.