CVE-2006-1983
published 2006-04-21CVE-2006-1983: Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via…
PriorityP430medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
7.92%
94.1th percentile
Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) PredictorVSetField function for TIFF or (2) CFAllocatorAllocate function for GIF, as used in applications that use ImageIO or AppKit. NOTE: the BMP vector has been re-assigned to CVE-2006-2238 because it affects a separate product family.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6477-j2rc-33qc: Multiple heap-based buffer overflows in Mac OS X 10
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2006-1983 [HIGH] CWE-119 GHSA-6477-j2rc-33qc: Multiple heap-based buffer overflows in Mac OS X 10
Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) PredictorVSetField function for TIFF or (2) CFAllocatorAllocate function for GIF, as used in applications that use ImageIO or AppKit. NOTE: the BMP vector has been re-assigned to CVE-2006-2238 because it affects a separate product family.
GHSA
GHSA-q5fr-275h-37w7: Heap-based buffer overflow in Apple QuickTime before 7
ghsa_unreviewed·2022-05-01·CVSS 6.4
CVE-2006-2238 [MEDIUM] CWE-119 GHSA-q5fr-275h-37w7: Heap-based buffer overflow in Apple QuickTime before 7
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted BMP file that triggers the overflow in the ReadBMP function. NOTE: this issue was originally included as item 3 in CVE-2006-1983, but it has been given a separate identifier because it is a distinct issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2006/May/msg00003.htmlhttp://secunia.com/advisories/19686http://secunia.com/advisories/20077http://securitytracker.com/id?1016067http://www.osvdb.org/24821http://www.osvdb.org/24822http://www.security-protocols.com/modules.php?name=News&file=article&sid=3233http://www.security-protocols.com/sp-x28-advisory.phphttp://www.security-protocols.com/sp-x30-advisory.phphttp://www.securityfocus.com/bid/17634http://www.securityfocus.com/bid/17951http://www.us-cert.gov/cas/techalerts/TA06-132A.htmlhttp://www.vupen.com/english/advisories/2006/1452http://www.vupen.com/english/advisories/2006/1779https://exchange.xforce.ibmcloud.com/vulnerabilities/25949https://exchange.xforce.ibmcloud.com/vulnerabilities/25951http://lists.apple.com/archives/security-announce/2006/May/msg00003.htmlhttp://secunia.com/advisories/19686http://secunia.com/advisories/20077http://securitytracker.com/id?1016067http://www.osvdb.org/24821http://www.osvdb.org/24822http://www.security-protocols.com/modules.php?name=News&file=article&sid=3233http://www.security-protocols.com/sp-x28-advisory.phphttp://www.security-protocols.com/sp-x30-advisory.phphttp://www.securityfocus.com/bid/17634http://www.securityfocus.com/bid/17951http://www.us-cert.gov/cas/techalerts/TA06-132A.htmlhttp://www.vupen.com/english/advisories/2006/1452http://www.vupen.com/english/advisories/2006/1779https://exchange.xforce.ibmcloud.com/vulnerabilities/25949https://exchange.xforce.ibmcloud.com/vulnerabilities/25951
2006-04-21
Published