Total
799 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-0063 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2010-03-30 | 6.8 MEDIUM | N/A |
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari, as demonstrated by the values for the (1) .ibplugin and (2) .url extensions. | |||||
CVE-2010-0064 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2010-03-30 | 6.9 MEDIUM | N/A |
DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticated Finder copy, which might allow local users to bypass intended disk-quota restrictions and have unspecified other impact by copying files owned by other users. | |||||
CVE-2009-2839 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-12-18 | 6.8 MEDIUM | N/A |
Screen Sharing in Apple Mac OS X 10.5.8 allows remote VNC servers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors. | |||||
CVE-2009-2823 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-23 | 4.3 MEDIUM | N/A |
The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software. | |||||
CVE-2009-2833 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-16 | 7.5 HIGH | N/A |
Buffer overflow in the UCCompareTextDefault API in International Components for Unicode in Apple Mac OS X 10.5.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. | |||||
CVE-2009-2840 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-16 | 4.9 MEDIUM | N/A |
Spotlight in Apple Mac OS X 10.5.8 does not properly handle temporary files, which allows local users to overwrite arbitrary files in the context of a different user's privileges via unspecified vectors. | |||||
CVE-2009-2832 | 1 Apple | 1 Mac Os X Server | 2009-11-16 | 5.1 MEDIUM | N/A |
Buffer overflow in FTP Server in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a CWD command specifying a pathname in a deeply nested hierarchy of directories, related to a "CWD command line tool." | |||||
CVE-2009-2836 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-16 | 6.2 MEDIUM | N/A |
Race condition in Login Window in Apple Mac OS X 10.6.x before 10.6.2, when at least one account has a blank password, allows attackers to bypass password authentication and obtain login access to an arbitrary account via unspecified vectors. | |||||
CVE-2009-2835 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-16 | 4.6 MEDIUM | N/A |
The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allows local users to gain privileges, cause a denial of service (system crash), or obtain sensitive information via unspecified vectors. | |||||
CVE-2009-2826 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-16 | 6.8 MEDIUM | N/A |
Multiple integer overflows in CoreGraphics in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers a heap-based buffer overflow. | |||||
CVE-2009-2810 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-16 | 6.8 MEDIUM | N/A |
Launch Services in Apple Mac OS X 10.6.x before 10.6.2 recursively clears quarantine information upon opening a quarantined folder, which allows user-assisted remote attackers to execute arbitrary code via a quarantined application that does not trigger a "potentially unsafe" warning message. | |||||
CVE-2009-2818 | 1 Apple | 1 Mac Os X Server | 2009-11-16 | 5.0 MEDIUM | N/A |
Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH login attempts, which makes it easier for remote attackers to obtain login access via a brute-force attack (aka dictionary attack). | |||||
CVE-2009-2819 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-16 | 9.3 HIGH | N/A |
AFP Client in Apple Mac OS X 10.5.8 allows remote AFP servers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via unspecified vectors. | |||||
CVE-2009-2824 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-16 | 6.8 MEDIUM | N/A |
Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code via a crafted embedded font in a document. | |||||
CVE-2009-2825 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-16 | 4.3 MEDIUM | N/A |
Certificate Assistant in Apple Mac OS X before 10.6.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. | |||||
CVE-2009-2827 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-16 | 6.8 MEDIUM | N/A |
Heap-based buffer overflow in Disk Images in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FAT filesystem on a disk image. | |||||
CVE-2009-2828 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-16 | 7.5 HIGH | N/A |
The server in DirectoryService in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors. | |||||
CVE-2009-2829 | 1 Apple | 1 Mac Os X Server | 2009-11-16 | 5.0 MEDIUM | N/A |
Event Monitor in Apple Mac OS X 10.5.8 does not properly handle crafted authentication data sent to an SSH daemon, which allows remote attackers to cause a denial of service via vectors involving processing of XML log documents by other services, related to a "log injection" issue. | |||||
CVE-2009-2830 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-16 | 6.8 MEDIUM | N/A |
Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X 10.6.x before 10.6.2 allow user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Common Document Format (CDF) file. NOTE: this might overlap CVE-2009-1515. | |||||
CVE-2009-2831 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-16 | 5.8 MEDIUM | N/A |
Dictionary in Apple Mac OS X 10.5.8 allows remote attackers to create arbitrary files with any contents, and thereby execute arbitrary code, via crafted JavaScript, related to a "design issue." |