← Back

CVE-2002-0676

nvd nist
Published: Jul 11, 2002Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates.

Affected (6)

Products: Apple: Mac Os X
1 product
Mac Os X
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 10.1.1
Version 10.1.2
Version 10.1.3
Version 10.1.4
Version 10.1.5
Version 10.1

References (8)

Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.