CVE-2006-0388: Code Injection
Published Mar 3, 2006
·Updated
Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources.
Affected Software
32 affected components
Apple iOS and macOS=10.4.3
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.3.2
Apple Mac OS X Server=10.3.7
Apple Mac OS X Server=10.3.5
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.5
Apple iOS and macOS=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.3.3
Apple Mac OS X Server=10.4.4
Apple Mac OS X Server=10.4.1
Apple iOS and macOS=10.4.4
Apple Mac OS X Server=10.3.4
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.3.7
Apple Mac OS X Server=10.4
Apple Mac OS X Server=10.4.5
Apple iOS and macOS=10.3.6
Apple Mac OS X Server=10.3
Apple Mac OS X Server=10.3.8
Apple iOS and macOS=10.4
Apple Mac OS X Server=10.3.9
Apple iOS and macOS=10.3.8
Apple Mac OS X Server=10.3.1
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.3.3
Apple iOS and macOS=10.4.2
Apple iOS and macOS=10.3
Apple Mac OS X Server=10.3.6
Remediation
Patch Available
Patch Available
Patch Available
Event History
Mar 3, 2006
CVE Published
10:02 PM
Mar 4, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0388?
CVE-2006-0388 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2006-0388?
To fix CVE-2006-0388, update your Mac OS X to version 10.4.5 or later.
3
What systems are affected by CVE-2006-0388?
CVE-2006-0388 affects Mac OS X versions 10.3 and 10.4, specifically before 10.4.5.
4
What type of vulnerability is CVE-2006-0388?
CVE-2006-0388 is a vulnerability that allows remote attackers to execute arbitrary JavaScript via local resource redirection.
5
Can CVE-2006-0388 lead to data exposure?
Yes, CVE-2006-0388 can potentially lead to unauthorized access to local files by executing malicious scripts.