CVE-2006-2277

macOS 10.4 - Denial of Service via Crafted OpenEXR Image File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-2277. PoCs published by Christian.

AI-analyzed exploit summary The provided text describes a remote denial-of-service vulnerability in ImageIO due to improper handling of malicious OpenEXR image files. It references a binary exploit file but does not contain executable code or technical details.

Description

Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial of service (application crash) via a crafted OpenEXR (.exr) image file, which triggers the crash when opening a folder using Finder, displaying the image in Safari, or using Preview to open the file.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Christian · textdososx
https://www.exploit-db.com/exploits/27790

The provided text describes a remote denial-of-service vulnerability in ImageIO due to improper handling of malicious OpenEXR image files. It references a binary exploit file but does not contain executable code or technical details.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Theoretical
Target: ImageIO (versions affected by CVE-2006-2277)
No auth needed
Prerequisites: A vulnerable application using the ImageIO API · Ability to deliver a malicious OpenEXR file to the target
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17768
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/27780
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/432587/100/0/threaded
Issue Tracking x_refsource_confirm
https://github.com/openexr/openexr/issues/564

Scores

EPSS 0.0739
EPSS Percentile 93.8%

Details

Status published
Products (7)
apple/mac_os_x 10.4
apple/mac_os_x 10.4.1
apple/mac_os_x 10.4.2
apple/mac_os_x 10.4.3
apple/mac_os_x 10.4.4
apple/mac_os_x 10.4.5
apple/mac_os_x 10.4.6
Published May 10, 2006
Tracked Since Feb 18, 2026