Mac OS X
by Apple Inc.
CVEs (3,257)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-2501 | 0.00 | — | 0.04 | Aug 19, 2005 | Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Format (RTF) file. | |||
| CVE-2005-2521 | 0.00 | — | 0.00 | Aug 19, 2005 | Buffer overflow in traceroute in Mac OS X 10.3.9 allows local users to execute arbitrary code via unknown vectors. | |||
| CVE-2005-2507 | 0.00 | — | 0.06 | Aug 19, 2005 | Buffer overflow in Directory Services in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication. | |||
| CVE-2005-2505 | 0.00 | — | 0.02 | Aug 19, 2005 | Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation. | |||
| CVE-2005-2520 | 0.00 | — | 0.00 | Aug 19, 2005 | The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the same process, does not reset the suggested password list when the assistant is displayed, which allows attackers to view recently used passwords. | |||
| CVE-2005-2526 | 0.00 | — | 0.02 | Aug 19, 2005 | CUPS in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to cause a denial of service (CPU consumption) by sending a partial IPP request and closing the connection. | |||
| CVE-2005-2522 | 0.00 | — | 0.04 | Aug 19, 2005 | Safari in WebKit in Mac OS X 10.4 to 10.4.2 directly accesses URLs within PDF files without the normal security checks, which allows remote attackers to execute arbitrary code via links in a PDF file. | |||
| CVE-2005-2514 | 0.00 | — | 0.03 | Aug 19, 2005 | Buffer overflow in ping in Mac OS X 10.3.9 allows local users to execute arbitrary code. | |||
| CVE-2005-2517 | 0.00 | — | 0.01 | Aug 19, 2005 | Safari in Mac OS X 10.3.9 and 10.4.2 submits forms from an XSL formatted page to the next page that is browsed by the user, which causes form data to be sent to the wrong site. | |||
| CVE-2005-2516 | 0.00 | — | 0.05 | Aug 19, 2005 | Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands. | |||
| CVE-2005-2503 | 0.00 | — | 0.00 | Aug 19, 2005 | AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window. | |||
| CVE-2005-2509 | 0.00 | — | 0.00 | Aug 19, 2005 | Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accounts. | |||
| CVE-2005-2506 | 0.00 | — | 0.01 | Aug 19, 2005 | Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates. | |||
| CVE-2005-2513 | 0.00 | — | 0.01 | Aug 19, 2005 | Unknown vulnerability in HItoolbox for Mac OS X 10.4.2 allows VoiceOver services to read secure input fields. | |||
| CVE-2005-1722 | 0.00 | — | 0.00 | Jun 16, 2005 | Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root sessions. | |||
| CVE-2005-1933 | 0.00 | — | 0.02 | Jun 13, 2005 | Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474. | |||
| CVE-2005-1473 | 0.00 | — | 0.00 | Jun 13, 2005 | SecurityAgent in Apple Mac OS X 10.4.1 allows attackers with physical access to bypass the locked screensaver and launch background applications by opening a URL from a text input field. | |||
| CVE-2005-1474 | 0.00 | — | 0.01 | Jun 13, 2005 | Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933. | |||
| CVE-2005-1727 | 0.00 | — | 0.00 | Jun 8, 2005 | Apple Mac OS X 10.4.x up to 10.4.1 sets insecure world- and group-writable permissions for the (1) system cache folder and (2) Dashboard system widgets, which allows local users to conduct unauthorized file operations via "file race conditions." | |||
| CVE-2005-1724 | 0.00 | — | 0.01 | Jun 8, 2005 | NFS on Apple Mac OS X 10.4.x up to 10.4.1 does not properly obey the -network or -mask flags for a filesystem and exports it to everyone, which allows remote attackers to bypass intended access restrictions. |
- CVE-2005-2501Aug 19, 2005risk 0.00cvss —epss 0.04
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Format (RTF) file.
- CVE-2005-2521Aug 19, 2005risk 0.00cvss —epss 0.00
Buffer overflow in traceroute in Mac OS X 10.3.9 allows local users to execute arbitrary code via unknown vectors.
- CVE-2005-2507Aug 19, 2005risk 0.00cvss —epss 0.06
Buffer overflow in Directory Services in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.
- CVE-2005-2505Aug 19, 2005risk 0.00cvss —epss 0.02
Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation.
- CVE-2005-2520Aug 19, 2005risk 0.00cvss —epss 0.00
The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the same process, does not reset the suggested password list when the assistant is displayed, which allows attackers to view recently used passwords.
- CVE-2005-2526Aug 19, 2005risk 0.00cvss —epss 0.02
CUPS in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to cause a denial of service (CPU consumption) by sending a partial IPP request and closing the connection.
- CVE-2005-2522Aug 19, 2005risk 0.00cvss —epss 0.04
Safari in WebKit in Mac OS X 10.4 to 10.4.2 directly accesses URLs within PDF files without the normal security checks, which allows remote attackers to execute arbitrary code via links in a PDF file.
- CVE-2005-2514Aug 19, 2005risk 0.00cvss —epss 0.03
Buffer overflow in ping in Mac OS X 10.3.9 allows local users to execute arbitrary code.
- CVE-2005-2517Aug 19, 2005risk 0.00cvss —epss 0.01
Safari in Mac OS X 10.3.9 and 10.4.2 submits forms from an XSL formatted page to the next page that is browsed by the user, which causes form data to be sent to the wrong site.
- CVE-2005-2516Aug 19, 2005risk 0.00cvss —epss 0.05
Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands.
- CVE-2005-2503Aug 19, 2005risk 0.00cvss —epss 0.00
AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window.
- CVE-2005-2509Aug 19, 2005risk 0.00cvss —epss 0.00
Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accounts.
- CVE-2005-2506Aug 19, 2005risk 0.00cvss —epss 0.01
Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates.
- CVE-2005-2513Aug 19, 2005risk 0.00cvss —epss 0.01
Unknown vulnerability in HItoolbox for Mac OS X 10.4.2 allows VoiceOver services to read secure input fields.
- CVE-2005-1722Jun 16, 2005risk 0.00cvss —epss 0.00
Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root sessions.
- CVE-2005-1933Jun 13, 2005risk 0.00cvss —epss 0.02
Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.
- CVE-2005-1473Jun 13, 2005risk 0.00cvss —epss 0.00
SecurityAgent in Apple Mac OS X 10.4.1 allows attackers with physical access to bypass the locked screensaver and launch background applications by opening a URL from a text input field.
- CVE-2005-1474Jun 13, 2005risk 0.00cvss —epss 0.01
Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.
- CVE-2005-1727Jun 8, 2005risk 0.00cvss —epss 0.00
Apple Mac OS X 10.4.x up to 10.4.1 sets insecure world- and group-writable permissions for the (1) system cache folder and (2) Dashboard system widgets, which allows local users to conduct unauthorized file operations via "file race conditions."
- CVE-2005-1724Jun 8, 2005risk 0.00cvss —epss 0.01
NFS on Apple Mac OS X 10.4.x up to 10.4.1 does not properly obey the -network or -mask flags for a filesystem and exports it to everyone, which allows remote attackers to bypass intended access restrictions.
Page 157 of 163