Vulnerability Name: | CVE-2006-1444 (CCN-26409) | ||||||||
Assigned: | 2006-05-11 | ||||||||
Published: | 2006-05-11 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | CoreGraphics in Apple Mac OS X 10.4.6, when "Enable access for assistive devices" is on, allows an application to bypass restrictions for secure event input and read certain events from other applications in the same window session by using Quartz Event Services. Successful exploitation requires that "Enable access for assistive devices" is on. This vulnerability is addressed in the following product release: Apple, Mac OS X, 10.4.6 (2006-003) | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-1444 Source: CCN Type: Apple Security Update 2006-003 About Security Update 2006-003 Source: APPLE Type: Patch APPLE-SA-2006-05-11 Source: CCN Type: SA20077 Mac OS X Security Update Fixes Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 20077 Source: CCN Type: SECTRACK ID: 1016079 Apple Mac OS X CoreGraphics May Let Local Users Obtain Secure Text Field Inputs Source: SECTRACK Type: UNKNOWN 1016079 Source: OSVDB Type: UNKNOWN 25588 Source: CCN Type: OSVDB ID: 25588 Apple Mac OS X CoreGraphics Quartz Event Services Event Interception Source: BID Type: UNKNOWN 17951 Source: CCN Type: BID-17951 Apple Mac OS X Security Update 2006-003 Multiple Vulnerabilities Source: CCN Type: US-CERT Technical Cyber Security Alert TA06-132A Apple Mac Products Affected by Multiple Vulnerabilities Source: CERT Type: US Government Resource TA06-132A Source: VUPEN Type: UNKNOWN ADV-2006-1779 Source: XF Type: UNKNOWN macos-coregraphics-quartz-security-bypass(26409) Source: XF Type: UNKNOWN macos-coregraphics-quartz-security-bypass(26409) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |