Total
5524 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-4394 | 1 Apple | 1 Mac Os X | 2017-07-19 | 7.5 HIGH | N/A |
A logic error in LoginWindow in Apple Mac OS X 10.4 through 10.4.7, allows network accounts without GUIds to bypass service access controls and log into the system using loginwindow via unknown vectors. | |||||
CVE-2006-4395 | 1 Apple | 1 Mac Os X | 2017-07-19 | 5.1 MEDIUM | N/A |
Unspecified vulnerability in QuickDraw Manager in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows context-dependent attackers to cause a denial of service ("memory corruption" and crash) via a crafted PICT image that is not properly handled by a certain "unsupported QuickDraw operation." | |||||
CVE-2006-4399 | 1 Apple | 1 Mac Os X | 2017-07-19 | 2.1 LOW | N/A |
User interface inconsistency in Workgroup Manager in Apple Mac OS X 10.4 through 10.4.7 appears to allow administrators to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo parent, when such an operation is not actually supported, which could result in less secure password management than intended. | |||||
CVE-2006-4403 | 1 Apple | 1 Mac Os X | 2017-07-19 | 4.0 MEDIUM | N/A |
The FTP server in Apple Mac OS X 10.4.8 and earlier, when FTP Access is enabled, will crash when a login failure occurs with a valid user name, which allows remote attackers to cause a denial of service (crash) and enumerate valid usernames. | |||||
CVE-2006-4406 | 1 Apple | 1 Mac Os X | 2017-07-19 | 7.5 HIGH | N/A |
Buffer overflow in PPP on Apple Mac OS X 10.4.x up to 10.4.8 and 10.3.x up to 10.3.9, when PPPoE is enabled, allows remote attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2006-4402 | 1 Apple | 1 Mac Os X | 2017-07-19 | 5.1 MEDIUM | N/A |
Heap-based buffer overflow in the Finder in Apple Mac OS X 10.4.8 and earlier allows user-assisted remote attackers to execute arbitrary code by browsing directories containing crafted .DS_Store files. | |||||
CVE-2006-5710 | 2 Apple, Opendarwin | 2 Mac Os X, Darwin Kernel | 2017-07-19 | 7.5 HIGH | N/A |
The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via an 802.11 probe response frame without any valid information element (IE) fields after the header, which triggers a heap-based buffer overflow. | |||||
CVE-2006-3499 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 2.1 LOW | N/A |
The dynamic linker (dyld) in Apple Mac OS X 10.3.9 allows local users to obtain sensitive information via unspecified dynamic linker options that affect the use of standard error (stderr) by privileged applications. | |||||
CVE-2006-3500 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 7.2 HIGH | N/A |
The dynamic linker (dyld) in Apple Mac OS X 10.4.7 allows local users to execute arbitrary code via an "improperly handled condition" that leads to use of "dangerous paths," probably related to an untrusted search path vulnerability. | |||||
CVE-2006-3501 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 5.1 MEDIUM | N/A |
Integer overflow in ImageIO for Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Radiance image. | |||||
CVE-2006-3356 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 2.6 LOW | N/A |
The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to cause a denial of service (application crash) via an invalid tag value in a TIFF image, possibly triggering a null dereference. NOTE: This is a different issue than CVE-2006-1469. | |||||
CVE-2006-3502 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 5.1 MEDIUM | N/A |
Unspecified vulnerability in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GIF image that triggers a memory allocation failure that is not properly handled. | |||||
CVE-2006-3503 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 5.1 MEDIUM | N/A |
Integer overflow in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed GIF image. | |||||
CVE-2006-3495 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 2.1 LOW | N/A |
AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 stores reconnect keys in a world-readable file, which allows local users to obtain the keys and access files and folders of other users. | |||||
CVE-2006-3498 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 10.0 HIGH | N/A |
Stack-based buffer overflow in bootpd in the DHCP component for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to execute arbitrary code via a crafted BOOTP request. | |||||
CVE-2006-3496 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 5.0 MEDIUM | N/A |
AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (crash) via an invalid AFP request that triggers an unchecked error condition. | |||||
CVE-2006-3504 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 5.1 MEDIUM | N/A |
The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari. | |||||
CVE-2006-3505 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 7.5 HIGH | N/A |
WebKit in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML document that causes WebKit to access an object that has already been deallocated. | |||||
CVE-2006-3946 | 1 Apple | 2 Mac Os X, Safari | 2017-07-19 | 7.5 HIGH | N/A |
WebCore in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted HTML that triggers a "memory management error" in WebKit, possibly due to a buffer overflow, as originally reported for the KHTMLParser::popOneBlock function in Apple Safari 2.0.4 using Javascript that changes document.body.innerHTML within a DIV tag. | |||||
CVE-2006-1981 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2017-07-19 | 2.1 LOW | N/A |
Unspecified vulnerability in Java InputMethods on Mac OS X 10.4.5 may cause InputMethods to send input events for secure fields to the wrong text field, which might reveal the password to others who can view the screen. |