Back

CVE-2004-0486

HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execute arbitrary code, an issue that was originally reported as a directory traversal vulnerability in the Safari web browser using the runscript parameter in a help: URI handler.

Published: Jul 7, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (8)

Vendor Product Version
apple mac_os_x 10.3
apple mac_os_x 10.3.1
apple mac_os_x 10.3.2
apple mac_os_x 10.3.3
apple mac_os_x_server 10.3
apple mac_os_x_server 10.3.1
apple mac_os_x_server 10.3.2
apple mac_os_x_server 10.3.3

GitHub Security Advisory GHSA-r8x3-9gqm-vxgf

HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can...

Risk Scores

CVSS Score 7.6 / 10
EPSS Score 9.66%

Top 5% most likely to be exploited

Threat Score 33.3 / 100

Data Sources

NVD EPSS GitHub