CVE-2006-5710

macOS 10.4.8 - Remote Code Execution via Malformed 802.11 Probe Response Frame

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5710. PoCs published by H D Moore.

AI-analyzed exploit summary This is a working proof-of-concept exploit for CVE-2006-5710, targeting a memory corruption vulnerability in the Apple Airport driver for Orinoco-based cards. It sends malformed probe response frames to trigger arbitrary code execution in the kernel.

Description

The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via an 802.11 probe response frame without any valid information element (IE) fields after the header, which triggers a heap-based buffer overflow.

Exploits (1)

exploitdb WORKING POC VERIFIED
by H D Moore · rubydoshardware
https://www.exploit-db.com/exploits/2700

This is a working proof-of-concept exploit for CVE-2006-5710, targeting a memory corruption vulnerability in the Apple Airport driver for Orinoco-based cards. It sends malformed probe response frames to trigger arbitrary code execution in the kernel.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apple Airport driver (Orinoco-based cards, 1999-2003 PowerBooks, iMacs) on macOS 10.4.8
No auth needed
Prerequisites: Target system with vulnerable Apple Airport driver · Target system in active scanning mode
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (13)

Core 13
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4750
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017151
Vendor Advisory x_refsource_confirm
http://docs.info.apple.com/article.html?artnum=304829
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/30180
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4313
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20862
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23155
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/191336
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-333A.html
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22679
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/29965

Scores

EPSS 0.1807
EPSS Percentile 96.8%

Details

CWE
CWE-119
Status published
Products (2)
apple/mac_os_x 10.4.8
opendarwin/darwin_kernel 8.8.0
Published Nov 04, 2006
Tracked Since Feb 18, 2026