VYPR

Mac OS X

by Apple Inc.

CVEs (3,257)

  • CVE-2007-0023Jan 24, 2007
    risk 0.03cvss epss 0.02

    The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home directory, which is executed…

  • CVE-2007-0430Jan 23, 2007
    risk 0.03cvss epss 0.01

    The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.

  • CVE-2007-0267Jan 17, 2007
    risk 0.03cvss epss 0.01

    The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct…

  • CVE-2007-0229Jan 13, 2007
    risk 0.03cvss epss 0.01

    Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer…

  • CVE-2007-0117Jan 9, 2007
    risk 0.03cvss epss 0.05

    DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows attackers to gain privileges via a BOM file under /Library/Receipts/, which triggers arbitrary file permission changes upon…

  • CVE-2006-6173Nov 30, 2006
    risk 0.03cvss epss 0.01

    Buffer overflow in the shared_region_make_private_np function in vm/vm_unix.c in Mac OS X 10.4.6 and earlier allows local users to execute arbitrary code via (1) a small range count, which causes insufficient memory allocation, or (2) a large number of ranges in the…

  • CVE-2006-6130Nov 28, 2006
    risk 0.03cvss epss 0.01

    Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket.

  • CVE-2006-6129Nov 27, 2006
    risk 0.03cvss epss 0.01

    Integer overflow in the fatfile_getarch2 in Apple Mac OS X allows local users to cause a denial of service and possibly execute arbitrary code via a crafted Mach-O Universal program that triggers memory corruption.

  • CVE-2006-6062Nov 22, 2006
    risk 0.03cvss epss 0.06

    Unspecified vulnerability in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a malformed UDTO HFS+ disk image, such as with "bad sectors," which triggers memory corruption.

  • CVE-2006-6015Nov 21, 2006
    risk 0.03cvss epss 0.04

    Buffer overflow in the JavaScript implementation in Safari on Apple Mac OS X 10.4 allows remote attackers to cause a denial of service (application crash) via a long argument to the exec method of a regular expression.

  • CVE-2006-5836Nov 10, 2006
    risk 0.03cvss epss 0.01

    The fpathconf syscall function in bsd/kern/kern_descrip.c in the Darwin kernel (XNU) 8.8.1 in Apple Mac OS X allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a file descriptor with an unrecognized file type.

  • CVE-2006-4392Oct 3, 2006
    risk 0.03cvss epss 0.02

    The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to modify the child's thread…

  • CVE-2006-3507Sep 21, 2006
    risk 0.03cvss epss 0.01

    Multiple stack-based buffer overflows in the AirPort wireless driver on Apple Mac OS X 10.3.9 and 10.4.7 allow physically proximate attackers to execute arbitrary code by injecting crafted frames into a wireless network.

  • CVE-2006-4866Sep 19, 2006
    risk 0.03cvss epss 0.01

    Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.

  • CVE-2005-2713Dec 31, 2005
    risk 0.03cvss epss 0.01

    passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to create arbitrary world-writable files as root by specifying an alternate file in the password database option.

  • CVE-2005-2508Aug 19, 2005
    risk 0.03cvss epss 0.01

    dsidentity in Directory Services in Mac OS X 10.4.2 allows local users to add or remove user accounts.

  • CVE-2005-2523Aug 19, 2005
    risk 0.03cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2005-1725Jun 8, 2005
    risk 0.03cvss epss 0.01

    launchd 106 in Apple Mac OS X 10.4.x up to 10.4.1 allows local users to overwrite arbitrary files via a symlink attack on the socket file in an insecure temporary directory.

  • CVE-2005-1307May 17, 2005
    risk 0.03cvss epss 0.04

    The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled…

  • CVE-2005-0342May 2, 2005
    risk 0.03cvss epss 0.01

    The Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileges by creating a hard link from the .DS_Store file to an arbitrary file.

Page 93 of 163