TROYANOSYVIRUS
Back to CVEs

CVE-2014-8839

N/A

Description

Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to discover recipient IP addresses by including an inline image in an HTML e-mail message and logging HTTP requests for this image's URL.

CVE Details

CVSS v3.1 ScoreN/A
Published1/30/2015
Last Modified4/12/2025
Sourcenvd
Honeypot Sightings0

Affected Products

apple:mac_os_x

Weaknesses (CWE)

CWE-200

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.