First published: Thu Aug 03 2006(Updated: )
The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.7 | |
Apple Mac OS X Server | =10.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3504 has been classified as a moderate vulnerability due to the potential for executing malicious JavaScript in a local context.
To fix CVE-2006-3504, disable the 'Open 'safe' files after downloading' option in Safari or update to a later version of macOS that addresses this vulnerability.
CVE-2006-3504 affects Apple Mac OS X version 10.4.7 and Apple Mac OS X Server version 10.4.7.
CVE-2006-3504 can facilitate attacks through the execution of arbitrary JavaScript code when certain HTML files are identified as 'safe'.
While CVE-2006-3504 is an older vulnerability, its impact can still be a concern for users running unsupported or outdated versions of macOS.