Apple Security Advisories · March 2006 — Apple Security Advisories
6 advisories 6 CVEs

Apple-vendor CVEs for 2006-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2006-1249

OtherPoC exploitCRITICAL2006-03-19

Integer overflow in Apple QuickTime Player 7.0.3 and 7.0.4 and iTunes 6.0.1 and 6.0.2 allows remote attackers to execute arbitrary code via a FlashPix (FPX) image that contains a field that specifies a large number of blocks.

CVEs:CVE-2006-1249

Affected products

ProductStatusVendorPackageEcosystem
itunes affected apple
quicktime affected apple
Upstream advisory

CVE-2006-0396

macOSEPSS <= 49%HIGH2006-03-14

Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name value in an e-mail attachment sent in AppleDouble format, which triggers the...

CVEs:CVE-2006-0396

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2006-1552

macOSEPSS <= 49%CRITICAL2006-03-31

Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".

CVEs:CVE-2006-1552

Affected products

ProductStatusVendorPackageEcosystem
imageio affected apple
mac_os_x affected apple
mac_os_x_server affected apple
safari affected apple
Upstream advisory

CVE-2006-0389

macOSEPSS <= 49%CRITICAL2006-03-02

Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vectors involving RSS feeds.

CVEs:CVE-2006-0389

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2006-0400

macOSEPSS <= 49%HIGH2006-03-14

CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin policy and execute Javascript in other domains via unknown vectors involving "crafted archives."

CVEs:CVE-2006-0400

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2006-1220

macOSEPSS <= 49%HIGH2006-03-14

Integer overflow in the mach_msg_send function in the kernel for Mac OS X might allow local users to execute arbitrary code via unknown attack vectors related to a large message header size, which leads to a heap-based buffer overflow.

CVEs:CVE-2006-1220

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.