Filtered by vendor Apple
Subscribe
Total
10175 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2006-1471 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2018-10-18 | 4.6 MEDIUM | N/A |
Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file. | |||||
CVE-2006-1453 | 1 Apple | 1 Quicktime | 2018-10-18 | 5.1 MEDIUM | N/A |
Stack-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file containing malformed font information. | |||||
CVE-2006-1454 | 1 Apple | 1 Quicktime | 2018-10-18 | 5.1 MEDIUM | N/A |
Heap-based buffer overflow in Apple QuickTime before 7.1 allows remote attackers to execute arbitrary code via a crafted QuickDraw PICT image format file with malformed image data. | |||||
CVE-2006-1249 | 1 Apple | 2 Itunes, Quicktime | 2018-10-18 | 6.8 MEDIUM | N/A |
Integer overflow in Apple QuickTime Player 7.0.3 and 7.0.4 and iTunes 6.0.1 and 6.0.2 allows remote attackers to execute arbitrary code via a FlashPix (FPX) image that contains a field that specifies a large number of blocks. | |||||
CVE-2006-6015 | 1 Apple | 1 Mac Os X | 2018-10-17 | 5.0 MEDIUM | N/A |
Buffer overflow in the JavaScript implementation in Safari on Apple Mac OS X 10.4 allows remote attackers to cause a denial of service (application crash) via a long argument to the exec method of a regular expression. | |||||
CVE-2006-4965 | 1 Apple | 1 Quicktime | 2018-10-17 | 5.0 MEDIUM | N/A |
Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outside of the original domain. NOTE: as of 20070912, this issue has been demonstrated by using instances of Components.interfaces.nsILocalFile and Components.interfaces.nsIProcess to execute arbitrary local files within Firefox and possibly Internet Explorer. | |||||
CVE-2006-4381 | 1 Apple | 1 Quicktime | 2018-10-17 | 5.1 MEDIUM | N/A |
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted H.264 movie. | |||||
CVE-2006-4382 | 1 Apple | 1 Quicktime | 2018-10-17 | 5.1 MEDIUM | N/A |
Multiple buffer overflows in Apple QuickTime before 7.1.3 allow user-assisted remote attackers to execute arbitrary code via a crafted QuickTime movie. | |||||
CVE-2006-4384 | 1 Apple | 1 Quicktime | 2018-10-17 | 5.1 MEDIUM | N/A |
Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via the COLOR_64 chunk in a FLIC (FLC) movie. | |||||
CVE-2006-4386 | 1 Apple | 1 Quicktime | 2018-10-17 | 5.1 MEDIUM | N/A |
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted H.264 movie, a different issue than CVE-2006-4381. | |||||
CVE-2006-4385 | 1 Apple | 1 Quicktime | 2018-10-17 | 5.1 MEDIUM | N/A |
Buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted SGI image. | |||||
CVE-2006-4388 | 1 Apple | 1 Quicktime | 2018-10-17 | 5.1 MEDIUM | N/A |
Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix file. | |||||
CVE-2006-4392 | 2 Apple, Next | 2 Mac Os X, Openstep | 2018-10-17 | 7.2 HIGH | N/A |
The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to modify the child's thread context and task address space in a way that causes the child to call a parent-controlled function. | |||||
CVE-2006-4389 | 1 Apple | 1 Quicktime | 2018-10-17 | 5.1 MEDIUM | N/A |
Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix (FPX) file, which triggers an exception that leads to an operation on an uninitialized object. | |||||
CVE-2006-6652 | 2 Apple, Netbsd | 2 Mac Os X, Netbsd | 2018-10-17 | 9.0 HIGH | N/A |
Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute arbitrary code via a long pathname that results from path expansion. | |||||
CVE-2015-3153 | 5 Apple, Canonical, Debian and 2 more | 6 Mac Os X, Ubuntu Linux, Debian Linux and 3 more | 2018-10-16 | 5.0 MEDIUM | N/A |
The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents. | |||||
CVE-2007-3274 | 2 Apple, Microsoft | 2 Safari, Windows Xp | 2018-10-16 | 4.3 MEDIUM | N/A |
Apple Safari 3.0 and 3.0.1 on Windows XP SP2 allows attackers to cause a denial of service (application crash) via JavaScript that sets the document.location variable, as demonstrated by an empty value of document.location. | |||||
CVE-2007-3073 | 3 Apple, Mozilla, Unix | 3 Mac Os X, Firefox, Unix | 2018-10-16 | 7.8 HIGH | N/A |
Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earlier on Mac OS X and Unix allows remote attackers to read arbitrary files via ..%2F (dot dot encoded slash) sequences in a resource:// URI. | |||||
CVE-2007-3186 | 1 Apple | 1 Safari | 2018-10-16 | 9.3 HIGH | N/A |
Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI. | |||||
CVE-2007-2580 | 1 Apple | 1 Safari | 2018-10-16 | 1.9 LOW | N/A |
Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords) via the document.loginform.password.value JavaScript parameter loaded from an AppleScript script. |