Apple Security Advisories · December 2006 — Apple Security Advisories
7 advisories 7 CVEs

Apple-vendor CVEs for 2006-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2006-6652

macOSEPSS <= 49%HIGH2006-12-01

Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute ar...

CVEs:CVE-2006-6652

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-5681

macOSEPSS <= 49%HIGH2006-12-20

QuickTime for Java on Mac OS X 10.4 through 10.4.8, when used with Quartz Composer, allows remote attackers to obtain sensitive information (screen images) via a Java applet that accesses images that are being rendered by other embedded QuickTime objects.

CVEs:CVE-2006-5681

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2006-6900

macOSEPSS <= 49%HIGH2006-12-31

Unspecified vulnerability in the Bluetooth stack in Apple Mac OS 10.4 has unknown impact and attack vectors, related to an "implementation bug."

CVEs:CVE-2006-6900

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-6238

SafariEPSS <= 49%HIGH2006-12-03

The AutoFill feature in Apple Safari 2.0.4 does not properly verify that all automatically populated form fields are visible to the user, which allows remote attackers to obtain sensitive information, such as usernames and passwords, via input fields o...

CVEs:CVE-2006-6238

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2006-6353

macOSEPSS <= 49%HIGH2006-12-07

Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application crash) via unspecified vectors related to (1) certain KERN_PROTECTION_FAILURE thread crashes and (2) cer...

CVEs:CVE-2006-6353

Affected products

ProductStatusVendorPackageEcosystem
bomarchivehelper affected apple
mac_os_x affected apple
mac_os_x_server affected apple
Upstream advisory

CVE-2006-6292

macOSEPSS <= 49%HIGH2006-12-05

Apple Airport Extreme firmware 0.1.27 in Mac OS X 10.4.8 on Mac mini, MacBook, and MacBook Pro with Core Duo hardware allows remote attackers to cause a denial of service (out-of-bounds memory access and kernel panic) and have possibly other security-r...

CVEs:CVE-2006-6292

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2006-6906

macOSEPSS <= 49%HIGH2006-12-31

Unspecified vulnerability in the Bluetooth stack on Mac OS 10.4.7 and earlier has unknown impact and local attack vectors, related to "Mach Exception Handling", a different issue than CVE-2006-6900.

CVEs:CVE-2006-6906

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.