Apple Security Advisories · May 2006 — Apple Security Advisories
29 advisories 29 CVEs

Apple-vendor CVEs for 2006-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2006-2238

OtherPoC exploitCRITICAL2006-05-12

Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted BMP file that triggers the overflow in the ReadBMP function. NOTE: this issue was originally included as item 3 in CVE-2006-1983, ...

CVEs:CVE-2006-2238

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2006-2277

macOSEPSS <= 49%HIGH2006-05-09

Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial of service (application crash) via a crafted OpenEXR (.exr) image file, which triggers the crash when opening a folder using Finder, displaying the imag...

CVEs:CVE-2006-2277

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1454

OtherEPSS <= 49%CRITICAL2006-05-12

Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file with malformed image data.

CVEs:CVE-2006-1454

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2006-1453

OtherEPSS <= 49%CRITICAL2006-05-12

Stack-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file containing malformed font information.

CVEs:CVE-2006-1453

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2006-1464

OtherEPSS <= 49%CRITICAL2006-05-12

Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime MPEG4 (M4P) video format file.

CVEs:CVE-2006-1464

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2006-1463

OtherEPSS <= 49%CRITICAL2006-05-12

Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a H.264 (M4V) video format file with a certain modified size value.

CVEs:CVE-2006-1463

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2006-1456

macOSEPSS <= 49%CRITICAL2006-05-12

Buffer overflow in QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted RTSP request, which is not properly handled during message logging.

CVEs:CVE-2006-1456

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2006-1460

OtherEPSS <= 49%CRITICAL2006-05-12

Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime movie (.MOV), as demonstrated via a large size for a udta Atom.

CVEs:CVE-2006-1460

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2006-1449

macOSEPSS <= 49%CRITICAL2006-05-12

Integer overflow in Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted MacMIME encapsulated attachment.

CVEs:CVE-2006-1449

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1450

macOSEPSS <= 49%CRITICAL2006-05-12

Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via an enriched text e-mail message with "invalid color information" that causes Mail to allocate and initialize arbitrary classes.

CVEs:CVE-2006-1450

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1461

OtherEPSS <= 49%CRITICAL2006-05-12

Multiple buffer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime Flash (SWF) file.

CVEs:CVE-2006-1461

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2006-1465

OtherEPSS <= 49%CRITICAL2006-05-12

Buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickTime AVI video format file.

CVEs:CVE-2006-1465

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2006-1459

OtherEPSS <= 49%CRITICAL2006-05-12

Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to cause a denial of service or execute arbitrary code via a crafted QuickTime movie (.MOV).

CVEs:CVE-2006-1459

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2006-1462

OtherEPSS <= 49%CRITICAL2006-05-12

Multiple integer overflows in Apple QuickTime before 7.1 allow remote attackers to execute arbitrary code via a crafted QuickTime H.264 (M4V) video format file.

CVEs:CVE-2006-1462

Affected products

ProductStatusVendorPackageEcosystem
quicktime affected apple
Upstream advisory

CVE-2006-1441

macOSEPSS <= 49%CRITICAL2006-05-12

Integer overflow in CFNetwork in Apple Mac OS X 10.4.6 allows remote attackers to execute arbitrary code via crafted chunked transfer encoding.

CVEs:CVE-2006-1441

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1455

macOSEPSS <= 49%HIGH2006-05-12

QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to cause a denial of service (crash and connection interruption) via a QuickTime movie with a missing track, which triggers a null dereference.

CVEs:CVE-2006-1455

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2006-1445

macOSEPSS <= 49%HIGH2006-05-12

Buffer overflow in the FTP server (FTPServer) in Apple Mac OS X 10.3.9 and 10.4.6 allows remote authenticated users to execute arbitrary code via vectors related to "FTP server path name handling."

CVEs:CVE-2006-1445

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1447

macOSEPSS <= 49%MEDIUM2006-05-12

LaunchServices in Apple Mac OS X 10.4.6 allows remote attackers to cause Safari to launch unsafe content via long file name extensions, which prevents Download Validation from determining which application will be used to open the file.

CVEs:CVE-2006-1447

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1442

macOSEPSS <= 49%CRITICAL2006-05-12

The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.

CVEs:CVE-2006-1442

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1446

macOSEPSS <= 49%MEDIUM2006-05-12

Keychain in Apple Mac OS X 10.3.9 and 10.4.6 might allow an application to bypass a locked Keychain by first obtaining a reference to the Keychain when it is unlocked, then reusing that reference after the Keychain has been locked.

CVEs:CVE-2006-1446

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1457

macOSEPSS <= 49%HIGH2006-05-12

Safari on Apple Mac OS X 10.4.6, when "Open `safe' files after downloading" is enabled, will automatically expand archives, which could allow remote attackers to overwrite arbitrary files via an archive that contains a symlink.

CVEs:CVE-2006-1457

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2006-1443

macOSEPSS <= 49%CRITICAL2006-05-12

Integer underflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving conversions from string to file system representation within (1) CFStringGetFileSyste...

CVEs:CVE-2006-1443

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1448

macOSEPSS <= 49%HIGH2006-05-12

Finder in Apple Mac OS X 10.3.9 and 10.4.6 allows user-assisted attackers to execute arbitrary code by tricking a user into launching an Internet Location item that appears to use a safe URL scheme, but which actually has a different and more risky sch...

CVEs:CVE-2006-1448

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1466

macOSEPSS <= 49%MEDIUM2006-05-24

Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.

CVEs:CVE-2006-1466

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
xcode affected apple
Upstream advisory

CVE-2006-1452

macOSEPSS <= 49%HIGH2006-05-12

Stack-based buffer overflow in Preview in Apple Mac OS 10.4 up to 10.4.6 allows local users to execute arbitrary code via a deep directory hierarchy.

CVEs:CVE-2006-1452

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1439

macOSEPSS <= 49%LOW2006-05-12

NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under certain circumstances, which could allow other applications in the window session to monitor input characters and keyboard events.

CVEs:CVE-2006-1439

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1451

macOSEPSS <= 49%HIGH2006-05-12

MySQL Manager in Apple Mac OS X 10.3.9 and 10.4.6, when setting up a new MySQL database server, does not use the "New MySQL root password" that is provided, which causes the MySQL root password to be blank and allows local users to gain full privileges...

CVEs:CVE-2006-1451

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1444

macOSEPSS <= 49%LOW2006-05-12

CoreGraphics in Apple Mac OS X 10.4.6, when "Enable access for assistive devices" is on, allows an application to bypass restrictions for secure event input and read certain events from other applications in the same window session by using Quartz Even...

CVEs:CVE-2006-1444

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-1440

macOSEPSS <= 49%HIGH2006-05-12

BOM in Apple Mac OS X 10.3.9 and 10.4.6 allows attackers to overwrite arbitrary files via an archive that contains symbolic links.

CVEs:CVE-2006-1440

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.