CVE-2009-1726 describes a heap-based buffer overflow in Apple's ColorSync component, affecting Mac OS X 10.4.11 and 10.5 prior to 10.5.8. This critical vulnerability, with a CVSS score of 9.3, allows remote attackers to execute arbitrary code or cause a denial of service through a crafted image containing an embedded ColorSync profile. While no active exploitation, public exploit code, or significant community discussion has been observed, its high severity and remote attack vector warrant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.5.6CPE matchmatch criteria | cpe:2.3:a:apple:mac_os_x:10.5.6:*:*:*:*:*:*:* | ||
10.4.11CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:* | ||
10.5CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:* | ||
10.5.0CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.5.0:*:*:*:*:*:*:* | ||
10.5.1CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.