Unrated severityNVD Advisory· Published Sep 16, 2008· Updated Apr 23, 2026
CVE-2008-3610
CVE-2008-3610
Description
Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.
Affected products
10cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:apple:mac_os_x:10.5:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.5.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.5.2:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.5.3:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:apple:mac_os_x_server:10.5:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x_server:10.5.1:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x_server:10.5.2:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x_server:10.5.3:*:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x_server:10.5.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- lists.apple.com/archives/security-announce//2008/Sep/msg00005.htmlnvdPatch
- www.securityfocus.com/bid/31189nvdPatch
- www.us-cert.gov/cas/techalerts/TA08-260A.htmlnvdUS Government Resource
- secunia.com/advisories/31882nvd
- securitytracker.com/idnvd
- www.vupen.com/english/advisories/2008/2584nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/45170nvd
News mentions
0No linked articles in our index yet.