VYPR

Mac OS X

by Apple Inc.

CVEs (3,257)

  • CVE-2007-0299Jan 17, 2007
    risk 0.00cvss —epss 0.04

    Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service (kernel panic) by mounting a crafted Unix File System (UFS) DMG image, which triggers an invalid pointer…

  • CVE-2006-6900Dec 31, 2006
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the Bluetooth stack in Apple Mac OS 10.4 has unknown impact and attack vectors, related to an "implementation bug."

  • CVE-2006-6906Dec 31, 2006
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the Bluetooth stack on Mac OS 10.4.7 and earlier has unknown impact and local attack vectors, related to "Mach Exception Handling", a different issue than CVE-2006-6900.

  • CVE-2006-5681Dec 20, 2006
    risk 0.00cvss —epss 0.02

    QuickTime for Java on Mac OS X 10.4 through 10.4.8, when used with Quartz Composer, allows remote attackers to obtain sensitive information (screen images) via a Java applet that accesses images that are being rendered by other embedded QuickTime objects.

  • CVE-2006-6353Dec 7, 2006
    risk 0.00cvss —epss 0.01

    Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application crash) via unspecified vectors related to (1) certain KERN_PROTECTION_FAILURE thread crashes and (2) certain KERN_INVALID_ADDRESS…

  • CVE-2006-6292Dec 5, 2006
    risk 0.00cvss —epss 0.01

    Apple Airport Extreme firmware 0.1.27 in Mac OS X 10.4.8 on Mac mini, MacBook, and MacBook Pro with Core Duo hardware allows remote attackers to cause a denial of service (out-of-bounds memory access and kernel panic) and have possibly other security-related impact via certain…

  • CVE-2006-4401Nov 30, 2006
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in CFNetwork in Mac OS 10.4.8 and earlier allows user-assisted remote attackers to execute arbitrary FTP commands via a crafted FTP URI.

  • CVE-2006-4408Nov 30, 2006
    risk 0.00cvss —epss 0.02

    The Security Framework in Apple Mac OS X 10.4 through 10.4.8 allows remote attackers to cause a denial of service (resource consumption) via certain public key values in an X.509 certificate that requires extra resources during signature verification. NOTE: this issue may be…

  • CVE-2006-4398Nov 30, 2006
    risk 0.00cvss —epss 0.01

    Multiple buffer overflows in the Apple Type Services (ATS) server in Mac OS X 10.4 through 10.4.8 allow local users to execute arbitrary code via crafted service requests.

  • CVE-2006-4410Nov 30, 2006
    risk 0.00cvss —epss 0.02

    The Security Framework in Apple Mac OS X 10.3.9, and 10.4.x before 10.4.7, does not properly search certificate revocation lists (CRL), which allows remote attackers to access systems by using revoked certificates.

  • CVE-2006-4407Nov 30, 2006
    risk 0.00cvss —epss 0.02

    The Security Framework in Apple Mac OS X 10.3.x up to 10.3.9 does not properly prioritize encryption ciphers when negotiating the strongest shared cipher, which causes Secure Transport to user a weaker cipher that makes it easier for remote attackers to decrypt traffic.

  • CVE-2006-4403Nov 30, 2006
    risk 0.00cvss —epss 0.04

    The FTP server in Apple Mac OS X 10.4.8 and earlier, when FTP Access is enabled, will crash when a login failure occurs with a valid user name, which allows remote attackers to cause a denial of service (crash) and enumerate valid usernames.

  • CVE-2006-4411Nov 30, 2006
    risk 0.00cvss —epss 0.00

    The VPN service in Apple Mac OS X 10.3.x through 10.3.9 and 10.4.x through 10.4.8 does not properly clean the environment when executing commands, which allows local users to gain privileges via unspecified vectors.

  • CVE-2006-4409Nov 30, 2006
    risk 0.00cvss —epss 0.02

    The Online Certificate Status Protocol (OCSP) service in the Security Framework in Apple Mac OS X 10.4 through 10.4.8 retrieve certificate revocation lists (CRL) when an HTTP proxy is in use, which could cause the system to accept certificates that have been revoked.

  • CVE-2006-4400Nov 30, 2006
    risk 0.00cvss —epss 0.05

    Stack-based buffer overflow in the Apple Type Services (ATS) server in Mac OS 10.4.8 and earlier allow user-assisted attackers to execute arbitrary code via crafted font files.

  • CVE-2006-4404Nov 30, 2006
    risk 0.00cvss —epss 0.02

    The Installer application in Apple Mac OS X 10.4.8 and earlier, when used by a user with Admin credentials, does not authenticate the user before installing certain software requiring system privileges.

  • CVE-2006-4396Nov 30, 2006
    risk 0.00cvss —epss 0.01

    The Apple Type Services (ATS) server in Mac OS X 10.4.8 and earlier does not securely create log files, which allows local users to create and modify arbitrary files via unspecified vectors, possibly relating to a symlink attack.

  • CVE-2006-4412Nov 30, 2006
    risk 0.00cvss —epss 0.05

    WebKit in Apple Mac OS X 10.3.x through 10.3.9 and 10.4 through 10.4.8 allows remote attackers to execute arbitrary code via a crafted HTML file, which accesses previously deallocated objects.

  • CVE-2006-6127Nov 27, 2006
    risk 0.00cvss —epss 0.00

    Apple Mac OS X kernel allows local users to cause a denial of service via a process that uses kevent to register a queue and an event, then fork a child process that uses kevent to register an event for the same queue as the parent.

  • CVE-2006-6126Nov 27, 2006
    risk 0.00cvss —epss 0.00

    Apple Mac OS X allows local users to cause a denial of service (memory corruption) via a crafted Mach-O binary with a malformed load_command data structure.

Page 151 of 163