CVE-2019-17051
30.09.2019, 20:15
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving a drag-and-drop operation on a crafted Terminal file.Enginsight
Vendor | Product | Version |
---|---|---|
evernote | evernote | 𝑥 < 7.13 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration