VYPR

Mac OS X

by Apple Inc.

CVEs (3,257)

  • CVE-2005-2501Aug 19, 2005
    risk 0.00cvss —epss 0.04

    Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Format (RTF) file.

  • CVE-2005-2521Aug 19, 2005
    risk 0.00cvss —epss 0.00

    Buffer overflow in traceroute in Mac OS X 10.3.9 allows local users to execute arbitrary code via unknown vectors.

  • CVE-2005-2507Aug 19, 2005
    risk 0.00cvss —epss 0.06

    Buffer overflow in Directory Services in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.

  • CVE-2005-2505Aug 19, 2005
    risk 0.00cvss —epss 0.02

    Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation.

  • CVE-2005-2520Aug 19, 2005
    risk 0.00cvss —epss 0.00

    The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the same process, does not reset the suggested password list when the assistant is displayed, which allows attackers to view recently used passwords.

  • CVE-2005-2526Aug 19, 2005
    risk 0.00cvss —epss 0.02

    CUPS in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to cause a denial of service (CPU consumption) by sending a partial IPP request and closing the connection.

  • CVE-2005-2522Aug 19, 2005
    risk 0.00cvss —epss 0.04

    Safari in WebKit in Mac OS X 10.4 to 10.4.2 directly accesses URLs within PDF files without the normal security checks, which allows remote attackers to execute arbitrary code via links in a PDF file.

  • CVE-2005-2514Aug 19, 2005
    risk 0.00cvss —epss 0.03

    Buffer overflow in ping in Mac OS X 10.3.9 allows local users to execute arbitrary code.

  • CVE-2005-2517Aug 19, 2005
    risk 0.00cvss —epss 0.01

    Safari in Mac OS X 10.3.9 and 10.4.2 submits forms from an XSL formatted page to the next page that is browsed by the user, which causes form data to be sent to the wrong site.

  • CVE-2005-2516Aug 19, 2005
    risk 0.00cvss —epss 0.05

    Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands.

  • CVE-2005-2503Aug 19, 2005
    risk 0.00cvss —epss 0.00

    AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window.

  • CVE-2005-2509Aug 19, 2005
    risk 0.00cvss —epss 0.00

    Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accounts.

  • CVE-2005-2506Aug 19, 2005
    risk 0.00cvss —epss 0.01

    Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates.

  • CVE-2005-2513Aug 19, 2005
    risk 0.00cvss —epss 0.01

    Unknown vulnerability in HItoolbox for Mac OS X 10.4.2 allows VoiceOver services to read secure input fields.

  • CVE-2005-1722Jun 16, 2005
    risk 0.00cvss —epss 0.00

    Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root sessions.

  • CVE-2005-1933Jun 13, 2005
    risk 0.00cvss —epss 0.02

    Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.

  • CVE-2005-1473Jun 13, 2005
    risk 0.00cvss —epss 0.00

    SecurityAgent in Apple Mac OS X 10.4.1 allows attackers with physical access to bypass the locked screensaver and launch background applications by opening a URL from a text input field.

  • CVE-2005-1474Jun 13, 2005
    risk 0.00cvss —epss 0.01

    Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.

  • CVE-2005-1727Jun 8, 2005
    risk 0.00cvss —epss 0.00

    Apple Mac OS X 10.4.x up to 10.4.1 sets insecure world- and group-writable permissions for the (1) system cache folder and (2) Dashboard system widgets, which allows local users to conduct unauthorized file operations via "file race conditions."

  • CVE-2005-1724Jun 8, 2005
    risk 0.00cvss —epss 0.01

    NFS on Apple Mac OS X 10.4.x up to 10.4.1 does not properly obey the -network or -mask flags for a filesystem and exports it to everyone, which allows remote attackers to bypass intended access restrictions.

Page 157 of 163