CVE-2001-1412
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 1.0%
from disclosure to weapon0 days
Published on NVDOct 25
1st PoCJun 26
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying passwd as a command line argument.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/20984⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://lists.apple.com/mhonarc/security-announce/msg00038.htmlhttp://lists.insecure.org/lists/bugtraq/2002/Sep/0128.htmlhttp://marc.info/?l=bugtraq&m=99953038722104&w=2http://securitytracker.com/id?1001946http://www.securemac.com/macosxnidump.phphttp://www.securiteam.com/securityreviews/5QP032A4UU.html