← Back to CVEs
CVE-2006-3504
N/ADescription
The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari.
CVE Details
CVSS v3.1 ScoreN/A
Published8/3/2006
Last Modified4/16/2026
Sourcenvd
Honeypot Sightings0
Affected Products
apple:mac_os_xapple:mac_os_x_server
References
http://secunia.com/advisories/21253(cve@mitre.org)
http://www.osvdb.org/27743(cve@mitre.org)
http://www.securityfocus.com/bid/19289(cve@mitre.org)
http://www.us-cert.gov/cas/techalerts/TA06-214A.html(cve@mitre.org)
http://www.vupen.com/english/advisories/2006/3101(cve@mitre.org)
https://exchange.xforce.ibmcloud.com/vulnerabilities/28146(cve@mitre.org)
http://lists.apple.com/archives/security-announce/2006//Aug/msg00000.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/21253(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/27743(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/19289(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/cas/techalerts/TA06-214A.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2006/3101(af854a3a-2127-422b-91ae-364da2661108)
https://exchange.xforce.ibmcloud.com/vulnerabilities/28146(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.