VYPR

Mac OS X Server

by Apple Inc.

CVEs (667)

  • CVE-2011-3460Feb 2, 2012
    risk 0.00cvss —epss 0.04

    Buffer overflow in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PNG file.

  • CVE-2011-3459Feb 2, 2012
    risk 0.00cvss —epss 0.03

    Off-by-one error in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted rdrf atom in a movie file that triggers a buffer overflow.

  • CVE-2011-3458Feb 2, 2012
    risk 0.00cvss —epss 0.03

    QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 file.

  • CVE-2011-3457Feb 2, 2012
    risk 0.00cvss —epss 0.03

    The OpenGL implementation in Apple Mac OS X before 10.7.3 does not properly perform OpenGL Shading Language (aka GLSL) compilation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted…

  • CVE-2011-3453Feb 2, 2012
    risk 0.00cvss —epss 0.04

    Integer overflow in libresolv in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via crafted DNS data.

  • CVE-2011-3452Feb 2, 2012
    risk 0.00cvss —epss 0.01

    Internet Sharing in Apple Mac OS X before 10.7.3 does not preserve the Wi-Fi configuration across software updates, which allows remote attackers to obtain sensitive information by leveraging the lack of a WEP password for a Wi-Fi network.

  • CVE-2011-3450Feb 2, 2012
    risk 0.00cvss —epss 0.03

    CoreUI in Apple Mac OS X 10.7.x before 10.7.3 does not properly restrict the allocation of stack memory, which allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and application crash) via a long URL.

  • CVE-2011-3449Feb 2, 2012
    risk 0.00cvss —epss 0.03

    Use-after-free vulnerability in CoreText in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.

  • CVE-2011-3448Feb 2, 2012
    risk 0.00cvss —epss 0.03

    Heap-based buffer overflow in CoreMedia in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.

  • CVE-2011-3447Feb 2, 2012
    risk 0.00cvss —epss 0.01

    CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL.

  • CVE-2011-3446Feb 2, 2012
    risk 0.00cvss —epss 0.03

    Apple Type Services (ATS) in Apple Mac OS X before 10.7.3 does not properly manage memory for data-font files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font that is accessed by Font Book.

  • CVE-2011-3444Feb 2, 2012
    risk 0.00cvss —epss 0.01

    Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.

  • CVE-2011-3437Oct 14, 2011
    risk 0.00cvss —epss 0.03

    Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a crafted embedded Type 1 font in a document.

  • CVE-2011-3436Oct 14, 2011
    risk 0.00cvss —epss 0.02

    Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by leveraging an unattended workstation.

  • CVE-2011-3435Oct 14, 2011
    risk 0.00cvss —epss 0.01

    Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of arbitrary users via unspecified vectors.

  • CVE-2011-3246Oct 14, 2011
    risk 0.00cvss —epss 0.03

    CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sites, via a crafted (1) http or (2) https URL.

  • CVE-2011-3228Oct 14, 2011
    risk 0.00cvss —epss 0.03

    QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.

  • CVE-2011-3227Oct 14, 2011
    risk 0.00cvss —epss 0.02

    libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1)…

  • CVE-2011-3226Oct 14, 2011
    risk 0.00cvss —epss 0.02

    Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypass the password requirement by leveraging lack of an AuthenticationAuthority attribute for a user account.

  • CVE-2011-3225Oct 14, 2011
    risk 0.00cvss —epss 0.02

    The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-restricted folder, which allows remote attackers to bypass intended browsing restrictions by leveraging access to the nobody…

Page 9 of 34