Mac OS X
by Apple Inc.
CVEs (3,257)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-0803 | 0.01 | — | 0.08 | Dec 23, 2004 | Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files. | |||
| CVE-2004-1307 | 0.01 | — | 0.06 | Dec 21, 2004 | Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a… | |||
| CVE-2004-0081 | 0.01 | — | 0.07 | Nov 23, 2004 | OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool. | |||
| CVE-2004-0112 | 0.01 | — | 0.10 | Nov 23, 2004 | The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake… | |||
| CVE-2004-0489 | 0.01 | — | 0.07 | Jul 7, 2004 | Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option. | |||
| CVE-2002-1369 | 0.01 | — | 0.08 | Dec 26, 2002 | jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack. | |||
| CVE-2002-1383 | 0.01 | — | 0.09 | Dec 26, 2002 | Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun. | |||
| CVE-2002-0655 | 0.01 | — | 0.08 | Aug 12, 2002 | OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code. | |||
| CVE-2022-26691 | Med | 0.00 | 6.7 | 0.01 | May 26, 2022 | A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges. | ||
| CVE-2022-23308 | Hig | 0.00 | 7.5 | 0.06 | Feb 26, 2022 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. | ||
| CVE-2022-0261 | Hig | 0.00 | 7.8 | 0.02 | Jan 18, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-0128 | Hig | 0.00 | 7.8 | 0.02 | Jan 6, 2022 | vim is vulnerable to Out-of-bounds Read | ||
| CVE-2021-4193 | Med | 0.00 | 5.5 | 0.02 | Dec 31, 2021 | vim is vulnerable to Out-of-bounds Read | ||
| CVE-2021-4192 | Hig | 0.00 | 7.8 | 0.02 | Dec 31, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-4187 | Hig | 0.00 | 7.8 | 0.02 | Dec 29, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-4173 | Hig | 0.00 | 7.8 | 0.02 | Dec 27, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-4166 | Hig | 0.00 | 7.1 | 0.02 | Dec 25, 2021 | vim is vulnerable to Out-of-bounds Read | ||
| CVE-2021-4136 | Hig | 0.00 | 7.8 | 0.02 | Dec 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2020-8037 | Hig | 0.00 | 7.5 | 0.03 | Nov 4, 2020 | The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. | ||
| CVE-2019-14868 | Hig | 0.00 | 7.4 | 0.01 | Apr 2, 2020 | In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to… |
- CVE-2004-0803Dec 23, 2004risk 0.01cvss —epss 0.08
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.
- CVE-2004-1307Dec 21, 2004risk 0.01cvss —epss 0.06
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a…
- CVE-2004-0081Nov 23, 2004risk 0.01cvss —epss 0.07
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
- CVE-2004-0112Nov 23, 2004risk 0.01cvss —epss 0.10
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake…
- CVE-2004-0489Jul 7, 2004risk 0.01cvss —epss 0.07
Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier allows remote attackers to (1) execute arbitrary code via the ProxyCommand option or (2) conduct port forwarding via the -R option.
- CVE-2002-1369Dec 26, 2002risk 0.01cvss —epss 0.08
jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.
- CVE-2002-1383Dec 26, 2002risk 0.01cvss —epss 0.09
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun.
- CVE-2002-0655Aug 12, 2002risk 0.01cvss —epss 0.08
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.
- risk 0.00cvss 6.7epss 0.01
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
- risk 0.00cvss 7.5epss 0.06
valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
- risk 0.00cvss 7.8epss 0.02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Out-of-bounds Read
- risk 0.00cvss 5.5epss 0.02
vim is vulnerable to Out-of-bounds Read
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Use After Free
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Use After Free
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Use After Free
- risk 0.00cvss 7.1epss 0.02
vim is vulnerable to Out-of-bounds Read
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.00cvss 7.5epss 0.03
The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.
- risk 0.00cvss 7.4epss 0.01
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to…
Page 100 of 163