VYPR

Mac OS X

by Apple Inc.

CVEs (3,257)

  • CVE-2013-5176Oct 24, 2013
    risk 0.00cvss epss 0.00

    The kernel in Apple Mac OS X before 10.9 does not properly handle integer values during unspecified tty device operations, which allows local users to cause a denial of service (system hang) by triggering a truncation error.

  • CVE-2013-5175Oct 24, 2013
    risk 0.00cvss epss 0.00

    The kernel in Apple Mac OS X before 10.9 allows local users to obtain sensitive information or cause a denial of service (out-of-bounds read and system crash) via a crafted Mach-O file.

  • CVE-2013-5174Oct 24, 2013
    risk 0.00cvss epss 0.00

    Integer signedness error in the kernel in Apple Mac OS X before 10.9 allows local users to cause a denial of service (system crash) via a crafted tty read operation.

  • CVE-2013-5173Oct 24, 2013
    risk 0.00cvss epss 0.00

    The random-number generator in the kernel in Apple Mac OS X before 10.9 provides lengthy exclusive access for processing of large requests, which allows local users to cause a denial of service (temporary generator outage) via an application that requires many random numbers.

  • CVE-2013-5172Oct 24, 2013
    risk 0.00cvss epss 0.01

    The kernel in Apple Mac OS X before 10.9 does not properly determine the output length for SHA-2 digest function calls, which allows context-dependent attackers to cause a denial of service (panic) by triggering a digest operation, as demonstrated by an IPSec connection.

  • CVE-2013-5171Oct 24, 2013
    risk 0.00cvss epss 0.00

    CoreGraphics in Apple Mac OS X before 10.9 allows local users to bypass secure input mode and log an arbitrary application's keystrokes via a hotkey event registration.

  • CVE-2013-5170Oct 24, 2013
    risk 0.00cvss epss 0.02

    Buffer underflow in CoreGraphics in Apple Mac OS X before 10.9 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.

  • CVE-2013-5169Oct 24, 2013
    risk 0.00cvss epss 0.00

    CoreGraphics in Apple Mac OS X before 10.9, when display-sleep mode is used, does not ensure that screen locking blocks the visibility of all windows, which allows physically proximate attackers to obtain sensitive information by reading the screen.

  • CVE-2013-5168Oct 24, 2013
    risk 0.00cvss epss 0.02

    Console in Apple Mac OS X before 10.9 allows user-assisted remote attackers to execute arbitrary applications by triggering a log entry with a crafted attached URL.

  • CVE-2013-5167Oct 24, 2013
    risk 0.00cvss epss 0.01

    CFNetwork in Apple Mac OS X before 10.9 does not properly support Safari's deletion of session cookies in response to a reset operation, which makes it easier for remote web servers to track users via Set-Cookie HTTP headers.

  • CVE-2013-5166Oct 24, 2013
    risk 0.00cvss epss 0.00

    The Bluetooth USB host controller in Apple Mac OS X before 10.9 prematurely deletes interfaces, which allows local users to cause a denial of service (system crash) via a crafted application.

  • CVE-2013-5165Oct 24, 2013
    risk 0.00cvss epss 0.02

    socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the --blockApp option, which allows remote attackers to bypass intended access restrictions via a network connection to an application for which blocking was configured.

  • CVE-2013-5163Oct 4, 2013
    risk 0.00cvss epss 0.00

    Directory Services in Apple Mac OS X before 10.8.5 Supplemental Update allows local users to bypass password-based authentication and modify arbitrary Directory Services records via unspecified vectors.

  • CVE-2011-2391Sep 19, 2013
    risk 0.00cvss epss 0.01

    The IPv6 implementation in the kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (CPU consumption) via crafted ICMPv6 packets.

  • CVE-2013-1824Sep 16, 2013
    risk 0.00cvss epss 0.04

    The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the…

  • CVE-2013-1033Sep 16, 2013
    risk 0.00cvss epss 0.02

    Screen Lock in Apple Mac OS X before 10.8.5 does not properly track sessions, which allows remote authenticated users to bypass locking by leveraging screen-sharing access.

  • CVE-2013-1032Sep 16, 2013
    risk 0.00cvss epss 0.03

    QuickTime in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted idsc atom in a QuickTime movie file.

  • CVE-2013-1031Sep 16, 2013
    risk 0.00cvss epss 0.00

    Power Management in Apple Mac OS X before 10.8.5 does not properly perform locking upon occurrences of a power assertion, which allows physically proximate attackers to bypass intended access restrictions by visiting an unattended workstation on which a locking failure had…

  • CVE-2013-1030Sep 16, 2013
    risk 0.00cvss epss 0.00

    mdmclient in Mobile Device Management in Apple Mac OS X before 10.8.5 places a password on the command line, which allows local users to obtain sensitive information by listing the process.

  • CVE-2013-1029Sep 16, 2013
    risk 0.00cvss epss 0.01

    The kernel in Apple Mac OS X before 10.8.5 allows remote attackers to cause a denial of service (panic) via crafted IGMP packets that leverage incorrect, extraneous code in the IGMP parser.

Page 125 of 163