VYPR

Mac OS X

by Apple Inc.

CVEs (3,257)

  • CVE-2011-3448Feb 2, 2012
    risk 0.00cvss epss 0.03

    Heap-based buffer overflow in CoreMedia in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.

  • CVE-2011-3447Feb 2, 2012
    risk 0.00cvss epss 0.01

    CFNetwork in Apple Mac OS X 10.7.x before 10.7.3 does not properly construct request headers during parsing of URLs, which allows remote attackers to obtain sensitive information via a malformed URL.

  • CVE-2011-3446Feb 2, 2012
    risk 0.00cvss epss 0.03

    Apple Type Services (ATS) in Apple Mac OS X before 10.7.3 does not properly manage memory for data-font files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font that is accessed by Font Book.

  • CVE-2011-3444Feb 2, 2012
    risk 0.00cvss epss 0.01

    Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.

  • CVE-2011-3919Jan 7, 2012
    risk 0.00cvss epss 0.02

    Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

  • CVE-2008-7303Nov 15, 2011
    risk 0.00cvss epss 0.04

    The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of launchctl to trigger the launchd daemon's…

  • CVE-2011-3437Oct 14, 2011
    risk 0.00cvss epss 0.03

    Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a crafted embedded Type 1 font in a document.

  • CVE-2011-3436Oct 14, 2011
    risk 0.00cvss epss 0.02

    Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allows remote attackers to bypass intended password-change restrictions by leveraging an unattended workstation.

  • CVE-2011-3435Oct 14, 2011
    risk 0.00cvss epss 0.01

    Open Directory in Apple Mac OS X 10.7 before 10.7.2 allows local users to read the password data of arbitrary users via unspecified vectors.

  • CVE-2011-3246Oct 14, 2011
    risk 0.00cvss epss 0.03

    CFNetwork in Apple iOS before 5.0.1 and Mac OS X 10.7 before 10.7.2 does not properly parse URLs, which allows remote attackers to trigger visits to unintended web sites, and transmission of cookies to unintended web sites, via a crafted (1) http or (2) https URL.

  • CVE-2011-3228Oct 14, 2011
    risk 0.00cvss epss 0.03

    QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file.

  • CVE-2011-3227Oct 14, 2011
    risk 0.00cvss epss 0.02

    libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1)…

  • CVE-2011-3226Oct 14, 2011
    risk 0.00cvss epss 0.02

    Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypass the password requirement by leveraging lack of an AuthenticationAuthority attribute for a user account.

  • CVE-2011-3225Oct 14, 2011
    risk 0.00cvss epss 0.02

    The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-restricted folder, which allows remote attackers to bypass intended browsing restrictions by leveraging access to the nobody…

  • CVE-2011-3224Oct 14, 2011
    risk 0.00cvss epss 0.02

    The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to App Store help information, which allows man-in-the-middle attackers to execute arbitrary code by spoofing the http server.

  • CVE-2011-3223Oct 14, 2011
    risk 0.00cvss epss 0.03

    Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLIC movie file.

  • CVE-2011-3222Oct 14, 2011
    risk 0.00cvss epss 0.03

    Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.

  • CVE-2011-3221Oct 14, 2011
    risk 0.00cvss epss 0.03

    QuickTime in Apple Mac OS X before 10.7.2 does not properly handle the atom hierarchy in movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file.

  • CVE-2011-3220Oct 14, 2011
    risk 0.00cvss epss 0.02

    QuickTime in Apple Mac OS X before 10.7.2 does not properly process URL data handlers in movie files, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.

  • CVE-2011-3218Oct 14, 2011
    risk 0.00cvss epss 0.01

    The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local…

Page 129 of 163