← All CVEs

CVE-2006-0848

medium · 5.1

The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloading a __MACOSX folder that contains metadata (resource fork) that invokes the Terminal, which automatically interprets the script using bash, as demonstrated using a ZIP file that contains a script with a safe file extension.

5.1
CVSS
58.1%
EPSS (exploit prob.)
99th
EPSS percentile
2006-02-22
Published

AV:N/AC:H/Au:N/C:P/I:P/A:P

Weaknesses

CWE-16

Affected products

VendorProductAffected versions
applemac_os_x10.4.5
applemac_os_x_server10.4.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-0848