← Vulnerability feed

Vulnerability record · CVE-2006-0395 · published 5 August 2006

CVE-2006-0395: Apple Mail Download Validation fails to flag unsafe attachment types

Apple · Mac Os X

The Download Validation feature in Mail on Mac OS X 10.4 does not correctly recognize attachment file types, so it fails to warn the user about unsafe types. Because the warning is missing, a user can be tricked into opening a crafted attachment that leads to code execution. The record does not specify which file types or versions are affected beyond Mac OS X 10.4 and Server.

5.1 CVSS 2.0 Medium EPSS 55% · top 1.0%
5.1CVSS 2.0 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user-assisted remote attackers to execute arbitrary code via crafted file types.

AV:N/AC:H/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityRequires user interaction and a specific legacy OS, but a missing security warning enables code execution and EPSS is high.

What it is

The Download Validation feature in Mail on Mac OS X 10.4 does not correctly recognize attachment file types, so it fails to warn the user about unsafe types. Because the warning is missing, a user can be tricked into opening a crafted attachment that leads to code execution. The record does not specify which file types or versions are affected beyond Mac OS X 10.4 and Server.

Impact

An attacker can execute arbitrary code in the context of the user who opens the crafted attachment. This gives code execution on the victim's system without a memory-corruption exploit, relying instead on the missing warning.

Attack surface

Reached remotely by sending an email with a crafted attachment to a Mail user; the CVSS vector AV:N/AC:H/Au:N indicates network delivery with no authentication, but successful exploitation requires the user to open the attachment.

Exploitation

Not listed in CISA KEV and no reference is tagged as exploit or proof-of-concept, though EPSS is high at 0.55376 (99th percentile). The record does not confirm public exploit code.

What to do

  • Apply the Apple security update referenced in Apple article 303382 (Mac OS X 10.4 era) or upgrade to a supported macOS release.
  • Disable automatic opening of attachments and configure Mail to not render or launch attachment content.
  • Train users not to open unexpected attachments and to verify sender intent out of band.
  • Block or quarantine risky attachment types at the mail gateway where feasible.

Detection

  • Monitor Mail application launches of processes spawned from attachment paths or temporary download directories.
  • Alert on execution of files originating from Mail's attachment storage locations.
  • Review mail gateway logs for attachment types that bypass or evade Download Validation warnings.
  • Correlate user reports of unexpected attachment behavior with process creation events on macOS endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-0395 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed8.8CVE-2022-2294Google Chrome WebRTC heap buffer overflow via crafted HTML pageCVE-2022-2294 is a heap buffer overflow in the WebRTC component of Google Chrome prior to 103.0.5060.114. A remote attacker can trigger heap corrupti…KEVEPSS 70%analysed8.8CVE-2021-1789Apple WebKit type confusion allows code execution via crafted web contentA type confusion flaw in Apple's WebKit engine was fixed through improved state handling across macOS, iOS, iPadOS, tvOS, watchOS and Safari. Process…KEVEPSS 14%analysed7.8CVE-2021-30713Apple macOS privacy preference bypass via missing authorizationmacOS Big Sur before 11.4 has a permissions validation flaw (CWE-862 missing authorization) that lets a malicious application bypass Privacy preferen…KEVEPSS 7.0%analysed

Source: NIST National Vulnerability Database (record CVE-2006-0395), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.