Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2006-1985

Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which triggers an error in the BOMStackPop function.

  • Published: Apr 22, 2006
  • Updated: Apr 13, 2023
  • CVE: CVE-2006-1985
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5.1
  • AV:N/AC:H/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
apple / safari 2.0.1 2.0.1.x
apple / safari 2.0.3 2.0.3.x
apple / safari 2.0.2 2.0.2.x
apple / safari 2.0 2.0.x
apple / mac_os_x 10.4.3 10.4.3.x
apple / mac_os_x_server 10.4.3 10.4.3.x
apple / mac_os_x_server 10.3.2 10.3.2.x
apple / mac_os_x_server 10.3.7 10.3.7.x
apple / mac_os_x_server 10.3.5 10.3.5.x
apple / mac_os_x 10.3.1 10.3.1.x
apple / mac_os_x 10.3.5 10.3.5.x
apple / mac_os_x 10.4.1 10.4.1.x
apple / mac_os_x_server 10.4.2 10.4.2.x
apple / mac_os_x_server 10.3.3 10.3.3.x
apple / mac_os_x_server 10.4.4 10.4.4.x
apple / mac_os_x_server 10.4.1 10.4.1.x
apple / mac_os_x 10.4.4 10.4.4.x
apple / mac_os_x_server 10.3.4 10.3.4.x
apple / mac_os_x 10.3.2 10.3.2.x
apple / mac_os_x 10.3.7 10.3.7.x
apple / mac_os_x_server 10.4 10.4.x
apple / mac_os_x_server 10.4.5 10.4.5.x
apple / mac_os_x 10.3.6 10.3.6.x
apple / mac_os_x_server 10.3 10.3.x
apple / mac_os_x_server 10.3.8 10.3.8.x
apple / mac_os_x 10.4 10.4.x
apple / mac_os_x_server 10.4.6 10.4.6.x
apple / mac_os_x_server 10.3.9 10.3.9.x
apple / mac_os_x 10.4.6 10.4.6.x
apple / mac_os_x 10.3.8 10.3.8.x
apple / mac_os_x_server 10.3.1 10.3.1.x
apple / mac_os_x 10.4.5 10.4.5.x
apple / mac_os_x 10.3.9 10.3.9.x
apple / mac_os_x 10.3.4 10.3.4.x
apple / mac_os_x 10.3.3 10.3.3.x
apple / mac_os_x 10.4.2 10.4.2.x
apple / mac_os_x 10.3 10.3.x
apple / mac_os_x_server 10.3.6 10.3.6.x