Vulnerability Details CVE-2006-1552
Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom".
Exploit prediction scoring system (EPSS) score
EPSS Score 0.038
EPSS Ranking 87.6%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2006-1552
-
cpe:2.3:a:apple:imageio:-
-
cpe:2.3:a:apple:safari:1.0
-
cpe:2.3:a:apple:safari:1.1
-
cpe:2.3:a:apple:safari:1.2
-
cpe:2.3:a:apple:safari:1.2.1
-
cpe:2.3:a:apple:safari:1.2.2
-
cpe:2.3:a:apple:safari:1.2.3
-
cpe:2.3:a:apple:safari:1.3
-
cpe:2.3:a:apple:safari:2.0
-
cpe:2.3:a:apple:safari:2.0.1
-
cpe:2.3:a:apple:safari:2.0.2
-
cpe:2.3:a:apple:safari:2.0_pre
-
cpe:2.3:a:apple:safari:beta2
-
cpe:2.3:o:apple:mac_os_x:10.4
-
cpe:2.3:o:apple:mac_os_x:10.4.1
-
cpe:2.3:o:apple:mac_os_x:10.4.2
-
cpe:2.3:o:apple:mac_os_x:10.4.3
-
cpe:2.3:o:apple:mac_os_x:10.4.4
-
cpe:2.3:o:apple:mac_os_x:10.4.5
-
cpe:2.3:o:apple:mac_os_x_server:10.4
-
cpe:2.3:o:apple:mac_os_x_server:10.4.1
-
cpe:2.3:o:apple:mac_os_x_server:10.4.2
-
cpe:2.3:o:apple:mac_os_x_server:10.4.3
-
cpe:2.3:o:apple:mac_os_x_server:10.4.4
-
cpe:2.3:o:apple:mac_os_x_server:10.4.5