CVE-2011-0178

The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory.
Severity
UNKNOWN
AV:L/AC:L/Au:N/C:P/I:N/A:N
Atk. Vector
LOCAL
Atk. Complexity
LOW
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
VendorProductVersion
applemac_os_x
𝑥
≤ 10.6.6
applemac_os_x
10.6.0
applemac_os_x
10.6.1
applemac_os_x
10.6.2
applemac_os_x
10.6.3
applemac_os_x
10.6.4
applemac_os_x
10.6.5
applecarboncore
*
applemac_os_x_server
𝑥
≤ 10.6.6
applemac_os_x_server
10.6.0
applemac_os_x_server
10.6.1
applemac_os_x_server
10.6.2
applemac_os_x_server
10.6.3
applemac_os_x_server
10.6.4
applemac_os_x_server
10.6.5
𝑥
= Vulnerable software versions