Back
CVE-2004-0489
Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option.
Published: Jul 7, 2004
Modified: Jun 16, 2026
CWE-88
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| apple | mac_os_x | * |
GitHub Security Advisory GHSA-q495-4rmw-2q38
Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier...
References (6)
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021871.html Broken Link
- http://www.insecure.ws/article.php?story=200405222251133 Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16242 Third Party Advisory, VDB Entry
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/021871.html Broken Link
- http://www.insecure.ws/article.php?story=200405222251133 Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16242 Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
7.6 / 10
EPSS Score
6.68%
Top 7% most likely to be exploited
Threat Score
32.4 / 100
Data Sources
NVD
EPSS
GitHub