Apple Security Advisories · November 2006 — Apple Security Advisories
33 advisories 33 CVEs

Apple-vendor CVEs for 2006-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2007-0197

macOSPoC exploitCRITICAL2006-11-23

Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.

CVEs:CVE-2007-0197

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2007-0021

OtherEPSS <= 49%CRITICAL2006-11-28

Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.

CVEs:CVE-2007-0021

Affected products

ProductStatusVendorPackageEcosystem
ichat affected apple
Upstream advisory

CVE-2007-0236

macOSEPSS <= 49%HIGH2006-11-28

Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (kernel panic) and possibly execute arbitrary code via a crafted AppleTalk request that tri...

CVEs:CVE-2007-0236

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2007-1071

macOSEPSS <= 49%CRITICAL2006-11-28

Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image that triggers the overflow during ...

CVEs:CVE-2007-1071

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2007-0463

macOSEPSS <= 49%CRITICAL2006-11-28

Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or u...

CVEs:CVE-2007-0463

Affected products

ProductStatusVendorPackageEcosystem
software_update affected apple
Upstream advisory

CVE-2006-6061

macOSEPSS <= 49%HIGH2006-11-20

com.apple.AppleDiskImageController in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via a malformed DMG image that triggers memory corruption. NOTE: the severity of this issue has been disputed b...

CVEs:CVE-2006-6061

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2007-0614

macOSEPSS <= 49%HIGH2006-11-28

The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.

CVEs:CVE-2007-0614

Affected products

ProductStatusVendorPackageEcosystem
ichat affected apple
instant_message_framework affected apple
mac_os_x affected apple
Upstream advisory

CVE-2007-0733

macOSEPSS <= 49%HIGH2006-11-28

Unspecified vulnerability in ImageIO in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted RAW image that triggers memor...

CVEs:CVE-2007-0733

Affected products

ProductStatusVendorPackageEcosystem
imageio affected apple
Upstream advisory

CVE-2007-0613

macOSEPSS <= 49%HIGH2006-11-10

The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entries when adding newly discovered available contacts, which allows remote attackers to cause a denial of ...

CVEs:CVE-2007-0613

Affected products

ProductStatusVendorPackageEcosystem
ichat affected apple
instant_message_framework affected apple
mdnsresponder affected apple
Upstream advisory

CVE-2007-0719

macOSEPSS <= 49%CRITICAL2006-11-28

Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via an image with a crafted ColorSync profile.

CVEs:CVE-2007-0719

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2007-0588

macOSEPSS <= 49%CRITICAL2006-11-28

The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a cra...

CVEs:CVE-2007-0588

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
quicktime affected apple
Upstream advisory

CVE-2006-6062

macOSEPSS <= 49%CRITICAL2006-11-20

Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a malformed UDTO HFS+ disk image, such as with "bad sectors," which triggers memory corruption.

CVEs:CVE-2006-6062

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2007-0102

macOSEPSS <= 49%CRITICAL2006-11-28

The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a (1...

CVEs:CVE-2007-0102

Affected products

ProductStatusVendorPackageEcosystem
preview affected apple
Upstream advisory

CVE-2007-0731

macOSEPSS <= 49%HIGH2006-11-28

Stack-based buffer overflow in the Apple-specific Samba module (SMB File Server) in Apple Mac OS X 10.4 through 10.4.8 allows context-dependent attackers to execute arbitrary code via a long ACL.

CVEs:CVE-2007-0731

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2006-6015

macOSEPSS <= 49%CRITICAL2006-11-21

Buffer overflow in the JavaScript implementation in Safari on Apple Mac OS X 10.4 allows remote attackers to cause a denial of service (application crash) via a long argument to the exec method of a regular expression.

CVEs:CVE-2006-6015

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2007-0722

macOSEPSS <= 49%CRITICAL2006-11-28

Integer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted AppleSingleEncoding disk image.

CVEs:CVE-2007-0722

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2007-0726

macOSEPSS <= 49%HIGH2006-11-28

The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote attackers to cause a denial of service by connecting to the server before SSH has finished creating keys, which causes the keys to be regenerated a...

CVEs:CVE-2007-0726

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2007-0299

macOSEPSS <= 49%CRITICAL2006-11-23

Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service (kernel panic) by mounting a crafted Unix File System (UFS) DMG image, which triggers ...

CVEs:CVE-2007-0299

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2007-0723

macOSEPSS <= 49%HIGH2006-11-28

Unspecified vulnerability in the authentication feature for DirectoryService (DS Plug-Ins) for Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote authenticated LDAP users to modify the root password and gain privileges via unknown vectors.

CVEs:CVE-2007-0723

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2007-0710

macOSEPSS <= 49%HIGH2006-11-28

The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614.

CVEs:CVE-2007-0710

Affected products

ProductStatusVendorPackageEcosystem
ichat affected apple
Upstream advisory

CVE-2007-0721

macOSEPSS <= 49%CRITICAL2006-11-28

Unspecified vulnerability in diskimages-helper in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted compressed disk image that triggers memory corruption.

CVEs:CVE-2007-0721

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2007-0318

macOSEPSS <= 49%HIGH2006-11-28

The do_hfs_truncate function in Mac OS X 10.4.8 allows context-dependent attackers to cause a denial of service (kernel panic) via a crafted HFS+ filesystem in a DMG image, which causes an access of an invalid vnode structure during file removal.

CVEs:CVE-2007-0318

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2007-0730

macOSEPSS <= 49%CRITICAL2006-11-28

Server Manager (servermgrd) in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently validate authentication credentials, which allows remote attackers to bypass authentication and modify system configuration.

CVEs:CVE-2007-0730

Affected products

ProductStatusVendorPackageEcosystem
server_manager affected apple
Upstream advisory

CVE-2007-0467

macOSEPSS <= 49%MEDIUM2006-11-28

crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on application logs in /Library/Logs/CrashReporter/.

CVEs:CVE-2007-0467

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2007-0023

macOSEPSS <= 49%MEDIUM2006-11-28

The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home dire...

CVEs:CVE-2007-0023

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-6173

macOSEPSS <= 49%HIGH2006-11-28

Buffer overflow in the shared_region_make_private_np function in vm/vm_unix.c in Mac OS X 10.4.6 and earlier allows local users to execute arbitrary code via (1) a small range count, which causes insufficient memory allocation, or (2) a large number of...

CVEs:CVE-2006-6173

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-6129

macOSEPSS <= 49%HIGH2006-11-26

Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a crafted Mach-O Universal program that triggers memory corruption.

CVEs:CVE-2006-6129

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2006-6130

macOSEPSS <= 49%MEDIUM2006-11-27

Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket.

CVEs:CVE-2006-6130

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2007-0267

macOSEPSS <= 49%HIGH2006-11-23

The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupte...

CVEs:CVE-2007-0267

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-6127

macOSEPSS <= 49%MEDIUM2006-11-27

Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as the parent.

CVEs:CVE-2006-6127

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2006-6126

macOSEPSS <= 49%HIGH2006-11-27

Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mach-O binary with a malformed load_command data structure.

CVEs:CVE-2006-6126

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2007-0728

macOSEPSS <= 49%MEDIUM2006-11-28

Unspecified vulnerability in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 creates files insecurely while initializing a USB printer, which allows local users to create or overwrite arbitrary files.

CVEs:CVE-2007-0728

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2006-4413

OtherEPSS <= 49%HIGH2006-11-18

Apple Remote Desktop before 3.1 uses insecure permissions for certain built-in packages, which allows local users on an Apple Remote Desktop administration system to modify the packages and gain root privileges on client systems that use the packages.

CVEs:CVE-2006-4413

Affected products

ProductStatusVendorPackageEcosystem
remote_desktop affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.