Lucene search

K
cveMitreCVE-2006-4390
HistoryOct 03, 2006 - 4:02 a.m.

CVE-2006-4390

2006-10-0304:02:00
mitre
web.nvd.nist.gov
35
cfnetwork
apple
mac os x
ssl
encryption
authentication
safari
identity
trusted sites
cve-2006-4390
nvd

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.005

Percentile

76.6%

CFNetwork in Apple Mac OS X 10.4 through 10.4.7 and 10.3.9 allows remote SSL sites to appear as trusted sites by using encryption without authentication, which can cause the lock icon in Safari to be displayed even when the site’s identity cannot be trusted.

Affected configurations

Nvd
Node
applemac_os_xMatch10.3.9
OR
applemac_os_xMatch10.4
OR
applemac_os_xMatch10.4.1
OR
applemac_os_xMatch10.4.2
OR
applemac_os_xMatch10.4.3
OR
applemac_os_xMatch10.4.4
OR
applemac_os_xMatch10.4.5
OR
applemac_os_xMatch10.4.6
OR
applemac_os_xMatch10.4.7
VendorProductVersionCPE
applemac_os_x10.3.9cpe:2.3:o:apple:mac_os_x:10.3.9:*:*:*:*:*:*:*
applemac_os_x10.4cpe:2.3:o:apple:mac_os_x:10.4:*:*:*:*:*:*:*
applemac_os_x10.4.1cpe:2.3:o:apple:mac_os_x:10.4.1:*:*:*:*:*:*:*
applemac_os_x10.4.2cpe:2.3:o:apple:mac_os_x:10.4.2:*:*:*:*:*:*:*
applemac_os_x10.4.3cpe:2.3:o:apple:mac_os_x:10.4.3:*:*:*:*:*:*:*
applemac_os_x10.4.4cpe:2.3:o:apple:mac_os_x:10.4.4:*:*:*:*:*:*:*
applemac_os_x10.4.5cpe:2.3:o:apple:mac_os_x:10.4.5:*:*:*:*:*:*:*
applemac_os_x10.4.6cpe:2.3:o:apple:mac_os_x:10.4.6:*:*:*:*:*:*:*
applemac_os_x10.4.7cpe:2.3:o:apple:mac_os_x:10.4.7:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.1

Confidence

Low

EPSS

0.005

Percentile

76.6%

Related for CVE-2006-4390