Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to discover recipient IP addresses by including an inline image in an HTML e-mail message and logging HTTP requests for this image's URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple Mac OS X Spotlight 信息泄露漏洞
Vulnerability Description
Apple OS X是美国苹果(Apple)公司为Mac计算机所开发的一套专用操作系统。Spotlight是其中的一个能够在输入框内快速检索整个系统(包含文件、邮件和联系方式等)的组件。 Apple Mac OS X 10.10.2之前版本的Spotlight中存在安全漏洞,该漏洞源于程序没有执行邮件中的‘Load remote content in messages’配置。攻击者可通过在HTML e-mail消息中插入内联图像,并记录该图像URL的HTTP请求利用该漏洞发现收件人的IP地址。
CVSS Information
N/A
Vulnerability Type
N/A