Back

CVE-2004-0489

Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option.

Published: Jul 7, 2004 Modified: Jun 16, 2026
CWE-88

CVSS Metrics

Affected Products (1)

Vendor Product Version
apple mac_os_x *

GitHub Security Advisory GHSA-q495-4rmw-2q38

Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier...

Risk Scores

CVSS Score 7.6 / 10
EPSS Score 6.68%

Top 7% most likely to be exploited

Threat Score 32.4 / 100

Data Sources

NVD EPSS GitHub