CVE Published: 30/03/2010 |
CVE Updated: 17/09/2024 |
CVE Year: 2010 Source: apple |
Vendor: n/a |
Product: n/a Status : PUBLISHED
CVE-2010-0063 Description
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari, as demonstrated by the values for the (1) .ibplugin and (2) .url extensions.