Filtered by vendor Apple
Subscribe
Total
10175 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-2872 | 2 Apple, Google | 2 Mac Os X, Chrome | 2013-07-10 | 5.0 MEDIUM | N/A |
Google Chrome before 28.0.1500.71 on Mac OS X does not ensure a sufficient source of entropy for renderer processes, which might make it easier for remote attackers to defeat cryptographic protection mechanisms in third-party components via unspecified vectors. | |||||
CVE-2007-0747 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2013-07-03 | 7.2 HIGH | N/A |
load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local users to gain privileges by setting unspecified environment variables. | |||||
CVE-2012-3718 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2013-06-05 | 2.1 LOW | N/A |
Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 allows local users to read passwords entered into Login Window (aka LoginWindow) or Screen Saver Unlock by installing an input method that intercepts keystrokes. | |||||
CVE-2013-3952 | 1 Apple | 1 Mac Os X | 2013-06-05 | 2.1 LOW | N/A |
The fill_pipeinfo function in bsd/kern/sys_pipe.c in the XNU kernel in Apple Mac OS X 10.8.x allows local users to defeat the KASLR protection mechanism via the PROC_PIDFDPIPEINFO option to the proc_info system call for a kernel pipe handle. | |||||
CVE-2013-1009 | 1 Apple | 1 Safari | 2013-06-05 | 6.8 MEDIUM | N/A |
WebKit, as used in Apple Safari before 6.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2013-1023. | |||||
CVE-2013-0984 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2013-06-05 | 9.3 HIGH | N/A |
Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted message. | |||||
CVE-2013-0982 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2013-06-05 | 1.7 LOW | N/A |
The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage of permanent cookies upon exit from Safari, which might allow physically proximate attackers to bypass cookie-based authentication by leveraging an unattended workstation. | |||||
CVE-2013-0975 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2013-06-05 | 6.8 MEDIUM | N/A |
Buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.8.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image. | |||||
CVE-2013-0983 | 1 Apple | 1 Mac Os X | 2013-06-05 | 6.8 MEDIUM | N/A |
Stack consumption vulnerability in CoreAnimation in Apple Mac OS X before 10.8.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted text glyph in a URL encountered by Safari. | |||||
CVE-2013-0985 | 1 Apple | 1 Mac Os X | 2013-06-05 | 2.1 LOW | N/A |
Disk Management in Apple Mac OS X before 10.8.4 does not properly authenticate attempts to disable FileVault, which allows local users to cause a denial of service (loss of encryption functionality) via an unspecified command line. | |||||
CVE-2013-0990 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2013-06-05 | 4.9 MEDIUM | N/A |
SMB in Apple Mac OS X before 10.8.4, when file sharing is enabled, allows remote authenticated users to create or modify files outside of a shared directory via unspecified vectors. | |||||
CVE-2013-1013 | 1 Apple | 1 Safari | 2013-06-05 | 4.3 MEDIUM | N/A |
XSS Auditor in WebKit in Apple Safari before 6.0.5 does not properly rewrite URLs, which allows remote attackers to trigger unintended form submissions via unspecified vectors. | |||||
CVE-2013-1023 | 1 Apple | 1 Safari | 2013-06-05 | 6.8 MEDIUM | N/A |
WebKit, as used in Apple Safari before 6.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2013-1009. | |||||
CVE-2013-3949 | 1 Apple | 1 Mac Os X | 2013-06-05 | 2.1 LOW | N/A |
The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not prevent use of the _POSIX_SPAWN_DISABLE_ASLR and _POSIX_SPAWN_ALLOW_DATA_EXEC flags for setuid and setgid programs, which allows local users to bypass intended access restrictions via a wrapper program that calls the posix_spawnattr_setflags function. | |||||
CVE-2013-0976 | 1 Apple | 1 Mac Os X | 2013-06-04 | 6.8 MEDIUM | N/A |
IOAcceleratorFamily in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted graphics image. | |||||
CVE-2010-2431 | 1 Apple | 1 Cups | 2013-05-14 | 2.6 LOW | N/A |
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file. | |||||
CVE-2010-2432 | 1 Apple | 1 Cups | 2013-05-14 | 5.0 MEDIUM | N/A |
The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to cause a denial of service (infinite loop) via HTTP_UNAUTHORIZED responses. | |||||
CVE-2010-1411 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2013-05-14 | 6.8 MEDIUM | N/A |
Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file that triggers a heap-based buffer overflow. | |||||
CVE-2010-0393 | 1 Apple | 1 Cups | 2013-05-14 | 6.9 MEDIUM | N/A |
The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine the file that provides localized message strings, which allows local users to gain privileges via a file that contains crafted localization data with format string specifiers. | |||||
CVE-2013-0886 | 2 Apple, Google | 2 Mac Os X, Chrome | 2013-04-10 | 7.5 HIGH | N/A |
Google Chrome before 25.0.1364.99 on Mac OS X does not properly implement signal handling for Native Client (aka NaCl) code, which has unspecified impact and attack vectors. |