MEDIUM · 5.0

CVE-2014-8839

Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to discover recipient IP addresses by including an inlin...

Vulnerability Description

Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to discover recipient IP addresses by including an inline image in an HTML e-mail message and logging HTTP requests for this image's URL.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AppleMac Os X<= 10.10.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-8839?

CVE-2014-8839 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to discover recipient IP addresses by including an inlin...

How severe is CVE-2014-8839?

CVE-2014-8839 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-8839?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os X.