VYPR

Mac OS X

by Apple Inc.

CVEs (3,257)

  • CVE-2006-1473Aug 2, 2006
    risk 0.00cvss epss 0.05

    Integer overflow in AFP Server for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors.

  • CVE-2006-3497Aug 2, 2006
    risk 0.00cvss epss 0.04

    Unspecified vulnerability in the "compression state handling" in Bom for Apple Mac OS X 10.3.9 and 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Zip archive.

  • CVE-2006-3495Aug 2, 2006
    risk 0.00cvss epss 0.01

    AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 stores reconnect keys in a world-readable file, which allows local users to obtain the keys and access files and folders of other users.

  • CVE-2006-1472Aug 2, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in AFP Server in Apple Mac OS X 10.3.9 allows remote attackers to determine names of unauthorized files and folders via unknown vectors related to the search results.

  • CVE-2006-3496Aug 2, 2006
    risk 0.00cvss epss 0.03

    AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (crash) via an invalid AFP request that triggers an unchecked error condition.

  • CVE-2006-3946Jul 31, 2006
    risk 0.00cvss epss 0.05

    WebCore in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted HTML that triggers a "memory management error" in WebKit, possibly due to a buffer overflow, as originally…

  • CVE-2006-3356Jul 6, 2006
    risk 0.00cvss epss 0.01

    The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to cause a denial of service (application crash) via an invalid tag value in a TIFF image, possibly triggering a null dereference. NOTE: This is a different issue…

  • CVE-2006-1471Jun 27, 2006
    risk 0.00cvss epss 0.00

    Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted…

  • CVE-2006-1469Jun 27, 2006
    risk 0.00cvss epss 0.05

    Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image.

  • CVE-2006-1468Jun 27, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Apple File Protocol (AFP) server in Apple Mac OS X 10.4 up to 10.4.6 includes the names of restricted files and folders within search results, which might allow remote attackers to obtain sensitive information.

  • CVE-2006-1466May 24, 2006
    risk 0.00cvss epss 0.02

    Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.

  • CVE-2006-1447May 12, 2006
    risk 0.00cvss epss 0.03

    LaunchServices in Apple Mac OS X 10.4.6 allows remote attackers to cause Safari to launch unsafe content via long file name extensions, which prevents Download Validation from determining which application will be used to open the file.

  • CVE-2006-1455May 12, 2006
    risk 0.00cvss epss 0.04

    QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to cause a denial of service (crash and connection interruption) via a QuickTime movie with a missing track, which triggers a null dereference.

  • CVE-2006-1452May 12, 2006
    risk 0.00cvss epss 0.00

    Stack-based buffer overflow in Preview in Apple Mac OS 10.4 up to 10.4.6 allows local users to execute arbitrary code via a deep directory hierarchy.

  • CVE-2006-1442May 12, 2006
    risk 0.00cvss epss 0.03

    The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.

  • CVE-2006-1439May 12, 2006
    risk 0.00cvss epss 0.00

    NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under certain circumstances, which could allow other applications in the window session to monitor input characters and keyboard events.

  • CVE-2006-1441May 12, 2006
    risk 0.00cvss epss 0.04

    Integer overflow in CFNetwork in Apple Mac OS X 10.4.6 allows remote attackers to execute arbitrary code via crafted chunked transfer encoding.

  • CVE-2006-1456May 12, 2006
    risk 0.00cvss epss 0.06

    Buffer overflow in QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted RTSP request, which is not properly handled during message logging.

  • CVE-2006-1448May 12, 2006
    risk 0.00cvss epss 0.02

    Finder in Apple Mac OS X 10.3.9 and 10.4.6 allows user-assisted attackers to execute arbitrary code by tricking a user into launching an Internet Location item that appears to use a safe URL scheme, but which actually has a different and more risky scheme.

  • CVE-2006-1449May 12, 2006
    risk 0.00cvss epss 0.05

    Integer overflow in Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted MacMIME encapsulated attachment.

Page 153 of 163