VYPR

Installer

by Apple Inc.

CVEs (2)

  • CVE-2007-0465Jan 31, 2007
    risk 0.05cvss epss 0.18

    Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.

  • CVE-2011-0190Mar 23, 2011
    risk 0.00cvss epss 0.01

    Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an Apple server.