Vulnerability Name: | CVE-2006-1439 (CCN-26404) | ||||||||
Assigned: | 2006-05-08 | ||||||||
Published: | 2006-05-08 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under certain circumstances, which could allow other applications in the window session to monitor input characters and keyboard events. This vulnerability is addressed in the following product release: Apple, Mac OS X, 10.4.6 (2006-003) | ||||||||
CVSS v3 Severity: | 2.8 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-200 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-1439 Source: CCN Type: Apple Security Update 2006-003 About Security Update 2006-003 Source: APPLE Type: Patch, Vendor Advisory APPLE-SA-2006-05-11 Source: CCN Type: SA20077 Mac OS X Security Update Fixes Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 20077 Source: OSVDB Type: UNKNOWN 25583 Source: CCN Type: OSVDB ID: 25583 Apple Mac OS X AppKit NSSecureTextField Input Disclosure Source: BID Type: UNKNOWN 17951 Source: CCN Type: BID-17951 Apple Mac OS X Security Update 2006-003 Multiple Vulnerabilities Source: CCN Type: US-CERT Technical Cyber Security Alert TA06-132A Apple Mac Products Affected by Multiple Vulnerabilities Source: CERT Type: US Government Resource TA06-132A Source: VUPEN Type: Vendor Advisory ADV-2006-1779 Source: XF Type: UNKNOWN macos-appkit-nssecuretext-weak-security(26404) Source: XF Type: UNKNOWN macos-appkit-nssecuretext-weak-security(26404) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |