SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-1447

LaunchServices in Apple Mac OS X 10.4.6 allows remote attackers to cause Safari to launch unsafe content via long file name extensions, which prevents Download Validation from determining which application will be used to open the file.

MEDIUM 5.0EPSS 3.13%

Does this matter?

Lower severity and a low EPSS score (3.13%). Track it; it rarely justifies an emergency change on its own.

Description

LaunchServices in Apple Mac OS X 10.4.6 allows remote attackers to cause Safari to launch unsafe content via long file name extensions, which prevents Download Validation from determining which application will be used to open the file.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
3.13% probability · 87th percentile
CISA KEV
Not listed
Affected
apple/mac os x
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.