CVE-2006-1450: High severity Apple iOS and macOS vulnerability
Published May 12, 2006
·Updated
Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via an enriched text e-mail message with "invalid color information" that causes Mail to allocate and initialize arbitrary classes.
Affected Software
2 affected components
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.3.9
Remediation
Event History
May 12, 2006
CVE Published
09:02 PM
May 13, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1450?
CVE-2006-1450 is considered a critical vulnerability that can allow remote code execution.
2
How do I fix CVE-2006-1450?
The fix for CVE-2006-1450 involves updating Apple Mail to a version that addresses this vulnerability.
3
Which versions of Mac OS X are affected by CVE-2006-1450?
CVE-2006-1450 affects Mac OS X versions 10.3.9 and 10.4.6.
4
What type of attack is associated with CVE-2006-1450?
CVE-2006-1450 is associated with a remote code execution attack via a malicious enriched text e-mail.
5
Can CVE-2006-1450 be exploited without user interaction?
Exploitation of CVE-2006-1450 typically requires the user to open a specially crafted email.