VYPR

Mac OS X

by Apple Inc.

CVEs (2,090)

  • CVE-2006-1471Jun 27, 2006
    risk 0.00cvss epss 0.00

    Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted…

  • CVE-2006-1469Jun 27, 2006
    risk 0.00cvss epss 0.05

    Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image.

  • CVE-2006-1468Jun 27, 2006
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Apple File Protocol (AFP) server in Apple Mac OS X 10.4 up to 10.4.6 includes the names of restricted files and folders within search results, which might allow remote attackers to obtain sensitive information.

  • CVE-2006-1466May 24, 2006
    risk 0.00cvss epss 0.02

    Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.

  • CVE-2006-1441May 12, 2006
    risk 0.00cvss epss 0.04

    Integer overflow in CFNetwork in Apple Mac OS X 10.4.6 allows remote attackers to execute arbitrary code via crafted chunked transfer encoding.

  • CVE-2006-1444May 12, 2006
    risk 0.00cvss epss 0.00

    CoreGraphics in Apple Mac OS X 10.4.6, when "Enable access for assistive devices" is on, allows an application to bypass restrictions for secure event input and read certain events from other applications in the same window session by using Quartz Event Services.

  • CVE-2006-1443May 12, 2006
    risk 0.00cvss epss 0.02

    Integer underflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving conversions from string to file system representation within (1) CFStringGetFileSystemRepresentation or (2)…

  • CVE-2006-1456May 12, 2006
    risk 0.00cvss epss 0.06

    Buffer overflow in QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted RTSP request, which is not properly handled during message logging.

  • CVE-2006-1448May 12, 2006
    risk 0.00cvss epss 0.02

    Finder in Apple Mac OS X 10.3.9 and 10.4.6 allows user-assisted attackers to execute arbitrary code by tricking a user into launching an Internet Location item that appears to use a safe URL scheme, but which actually has a different and more risky scheme.

  • CVE-2006-1452May 12, 2006
    risk 0.00cvss epss 0.00

    Stack-based buffer overflow in Preview in Apple Mac OS 10.4 up to 10.4.6 allows local users to execute arbitrary code via a deep directory hierarchy.

  • CVE-2006-1450May 12, 2006
    risk 0.00cvss epss 0.05

    Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via an enriched text e-mail message with "invalid color information" that causes Mail to allocate and initialize arbitrary classes.

  • CVE-2006-1440May 12, 2006
    risk 0.00cvss epss 0.00

    BOM in Apple Mac OS X 10.3.9 and 10.4.6 allows attackers to overwrite arbitrary files via an archive that contains symbolic links.

  • CVE-2006-1457May 12, 2006
    risk 0.00cvss epss 0.02

    Safari on Apple Mac OS X 10.4.6, when "Open `safe' files after downloading" is enabled, will automatically expand archives, which could allow remote attackers to overwrite arbitrary files via an archive that contains a symlink.

  • CVE-2006-1446May 12, 2006
    risk 0.00cvss epss 0.03

    Keychain in Apple Mac OS X 10.3.9 and 10.4.6 might allow an application to bypass a locked Keychain by first obtaining a reference to the Keychain when it is unlocked, then reusing that reference after the Keychain has been locked.

  • CVE-2006-1442May 12, 2006
    risk 0.00cvss epss 0.03

    The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.

  • CVE-2006-1449May 12, 2006
    risk 0.00cvss epss 0.05

    Integer overflow in Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted MacMIME encapsulated attachment.

  • CVE-2006-1447May 12, 2006
    risk 0.00cvss epss 0.03

    LaunchServices in Apple Mac OS X 10.4.6 allows remote attackers to cause Safari to launch unsafe content via long file name extensions, which prevents Download Validation from determining which application will be used to open the file.

  • CVE-2006-1455May 12, 2006
    risk 0.00cvss epss 0.04

    QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to cause a denial of service (crash and connection interruption) via a QuickTime movie with a missing track, which triggers a null dereference.

  • CVE-2006-1451May 12, 2006
    risk 0.00cvss epss 0.00

    MySQL Manager in Apple Mac OS X 10.3.9 and 10.4.6, when setting up a new MySQL database server, does not use the "New MySQL root password" that is provided, which causes the MySQL root password to be blank and allows local users to gain full privileges to that database.

  • CVE-2006-1445May 12, 2006
    risk 0.00cvss epss 0.04

    Buffer overflow in the FTP server (FTPServer) in Apple Mac OS X 10.3.9 and 10.4.6 allows remote authenticated users to execute arbitrary code via vectors related to "FTP server path name handling."

Page 95 of 105