CVE-2010-1803
published 2010-11-15CVE-2010-1803: Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its remote AFP volume, which allows remote attackers to obtain…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.70%
74.8th percentile
Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its remote AFP volume, which allows remote attackers to obtain sensitive information by spoofing this volume.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.7.2 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | <= 10.7.2 | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mmjm-vfgc-2fxf: Time Machine in Apple Mac OS X 10
ghsa_unreviewed·2022-05-17
CVE-2010-1803 [MEDIUM] GHSA-mmjm-vfgc-2fxf: Time Machine in Apple Mac OS X 10
Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its remote AFP volume, which allows remote attackers to obtain sensitive information by spoofing this volume.
GHSA
GHSA-r3mj-74qm-pv3m: Time Machine in Apple Mac OS X before 10
ghsa_unreviewed·2022-05-17·CVSS 4.3
CVE-2011-3462 [MEDIUM] GHSA-r3mj-74qm-pv3m: Time Machine in Apple Mac OS X before 10
Time Machine in Apple Mac OS X before 10.7.3 does not verify the unique identifier of its remote AFP volume or Time Capsule, which allows remote attackers to obtain sensitive information contained in new backups by spoofing this storage object, a different vulnerability than CVE-2010-1803.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2010-11-15
Published