Sploitus

CVE-2006-1982

1 known exploit for CVE-2006-1982

Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remote attackers to execute arbitrary code via crafted TIFF images.

Affected products
Appkit, Imageio, Macos X
Apple Mac Os X
= 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.3.7, 10.3.8, 10.3.9, 10.4, 10.4.1, 10.4.2, 10.4.3, 10.4.4, 10.4.5
Apple Mac Os X Server
= 10.3, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.3.7, 10.3.8, 10.3.9, 10.4, 10.4.1, 10.4.2, 10.4.3, 10.4.4, 10.4.5
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
19.9% (97th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2006-04-21
CVE-2006-1982 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2006-1982

Proof-of-concept code and exploit modules indexed by Sploitus