VYPR

Mac OS X

by Apple Inc.

CVEs (3,257)

  • CVE-2013-1028Sep 16, 2013
    risk 0.00cvss epss 0.01

    The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which allows man-in-the-middle attackers to spoof security gateways and obtain sensitive information via a crafted certificate.

  • CVE-2013-1027Sep 16, 2013
    risk 0.00cvss epss 0.02

    Installer in Apple Mac OS X before 10.8.5 provides an option to continue a package's installation after encountering a revoked certificate, which might allow user-assisted remote attackers to execute arbitrary code via a crafted package.

  • CVE-2013-1026Sep 16, 2013
    risk 0.00cvss epss 0.03

    Buffer overflow in ImageIO in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG2000 data in a PDF document.

  • CVE-2013-1025Sep 16, 2013
    risk 0.00cvss epss 0.03

    Buffer overflow in CoreGraphics in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JBIG2 data in a PDF document.

  • CVE-2013-3954Jun 5, 2013
    risk 0.00cvss epss 0.00

    The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not properly validate the data for file actions and port actions, which allows local users to (1) cause a denial of service (panic) via a size value that is inconsistent with a header count field, or (2)…

  • CVE-2013-3953Jun 5, 2013
    risk 0.00cvss epss 0.00

    The mach_port_space_info function in osfmk/ipc/mach_debug.c in the XNU kernel in Apple Mac OS X 10.8.x does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted call.

  • CVE-2013-3952Jun 5, 2013
    risk 0.00cvss epss 0.00

    The fill_pipeinfo function in bsd/kern/sys_pipe.c in the XNU kernel in Apple Mac OS X 10.8.x allows local users to defeat the KASLR protection mechanism via the PROC_PIDFDPIPEINFO option to the proc_info system call for a kernel pipe handle.

  • CVE-2013-3951Jun 5, 2013
    risk 0.00cvss epss 0.00

    sys/openbsd/stack_protector.c in libc in Apple iOS 6.1.3 and Mac OS X 10.8.x does not properly parse the Apple strings employed in the user-space stack-cookie implementation, which allows local users to bypass cookie randomization by executing a program with a call-path…

  • CVE-2013-3949Jun 5, 2013
    risk 0.00cvss epss 0.00

    The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not prevent use of the _POSIX_SPAWN_DISABLE_ASLR and _POSIX_SPAWN_ALLOW_DATA_EXEC flags for setuid and setgid programs, which allows local users to bypass intended access restrictions via a wrapper…

  • CVE-2013-1024Jun 5, 2013
    risk 0.00cvss epss 0.03

    CoreMedia Playback in Apple Mac OS X before 10.8.4 does not properly initialize memory during the processing of text tracks, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.

  • CVE-2013-0990Jun 5, 2013
    risk 0.00cvss epss 0.01

    SMB in Apple Mac OS X before 10.8.4, when file sharing is enabled, allows remote authenticated users to create or modify files outside of a shared directory via unspecified vectors.

  • CVE-2013-0985Jun 5, 2013
    risk 0.00cvss epss 0.00

    Disk Management in Apple Mac OS X before 10.8.4 does not properly authenticate attempts to disable FileVault, which allows local users to cause a denial of service (loss of encryption functionality) via an unspecified command line.

  • CVE-2013-0983Jun 5, 2013
    risk 0.00cvss epss 0.02

    Stack consumption vulnerability in CoreAnimation in Apple Mac OS X before 10.8.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted text glyph in a URL encountered by Safari.

  • CVE-2013-0982Jun 5, 2013
    risk 0.00cvss epss 0.00

    The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage of permanent cookies upon exit from Safari, which might allow physically proximate attackers to bypass cookie-based authentication by leveraging an unattended workstation.

  • CVE-2013-0975Jun 5, 2013
    risk 0.00cvss epss 0.03

    Buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.8.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.

  • CVE-2013-0986May 24, 2013
    risk 0.00cvss epss 0.05

    Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted enof atoms in a movie file.

  • CVE-2013-2777Apr 8, 2013
    risk 0.00cvss epss 0.00

    sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to a session…

  • CVE-2013-2776Apr 8, 2013
    risk 0.00cvss epss 0.00

    sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the…

  • CVE-2013-1776Apr 8, 2013
    risk 0.00cvss epss 0.00

    sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vectors related to connecting…

  • CVE-2013-0976Mar 15, 2013
    risk 0.00cvss epss 0.02

    IOAcceleratorFamily in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted graphics image.

Page 126 of 163