First published: Mon Mar 06 2006(Updated: )
Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via unspecified vectors involving a web page with crafted JavaScript, a different vulnerability than CVE-2005-4504.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.3 | |
Apple Mac OS X Server | =10.4.3 | |
Apple Mac OS X Server | =10.3.2 | |
Apple Mac OS X Server | =10.3.7 | |
Apple Mac OS X Server | =10.3.5 | |
macOS Yosemite | =10.3.1 | |
macOS Yosemite | =10.3.5 | |
macOS Yosemite | =10.4.1 | |
Apple Mac OS X Server | =10.4.2 | |
Apple Mac OS X Server | =10.3.3 | |
Apple Mac OS X Server | =10.4.4 | |
Apple Mac OS X Server | =10.4.1 | |
macOS Yosemite | =10.4.4 | |
Apple Mac OS X Server | =10.3.4 | |
macOS Yosemite | =10.3.2 | |
macOS Yosemite | =10.3.7 | |
Apple Mac OS X Server | =10.4 | |
Apple Mac OS X Server | =10.4.5 | |
macOS Yosemite | =10.3.6 | |
Apple Mac OS X Server | =10.3 | |
Apple Mac OS X Server | =10.3.8 | |
macOS Yosemite | =10.4 | |
Apple Mac OS X Server | =10.3.9 | |
macOS Yosemite | =10.3.8 | |
Apple Mac OS X Server | =10.3.1 | |
macOS Yosemite | =10.4.5 | |
macOS Yosemite | =10.3.9 | |
macOS Yosemite | =10.3.4 | |
macOS Yosemite | =10.3.3 | |
macOS Yosemite | =10.4.2 | |
macOS Yosemite | =10.3 | |
Apple Mac OS X Server | =10.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0387 has a high severity as it allows remote attackers to execute arbitrary code via a stack-based buffer overflow.
To fix CVE-2006-0387, you must upgrade to a version of macOS that is not vulnerable, specifically update to Mac OS X 10.4.6 or later.
CVE-2006-0387 affects Mac OS X versions 10.4.5 and earlier, as well as 10.3.9 and earlier.
CVE-2006-0387 allows attackers to execute arbitrary code remotely through crafted JavaScript on a web page.
There are no known workarounds for CVE-2006-0387 aside from upgrading to a secure version.