by Apple Inc.
CVEs (25)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-1505 | 0.00 | — | 0.01 | May 11, 2005 | The new account wizard in Mail.app 2.0 in Mac OS 10.4, when configuring an IMAP mail account and checking the credentials, does not prompt the user to use SSL until after the password has already been sent, which causes the password to be sent in plaintext. | |||
| CVE-2005-0127 | 0.00 | — | 0.03 | May 2, 2005 | Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine. | |||
| CVE-2004-0383 | 0.00 | — | 0.00 | May 4, 2004 | Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email." | |||
| CVE-2004-0086 | 0.00 | — | 0.01 | Mar 3, 2004 | Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085. | |||
| CVE-2003-0881 | 0.00 | — | 0.01 | Nov 3, 2003 | Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password. |
- CVE-2005-1505May 11, 2005risk 0.00cvss —epss 0.01
The new account wizard in Mail.app 2.0 in Mac OS 10.4, when configuring an IMAP mail account and checking the credentials, does not prompt the user to use SSL until after the password has already been sent, which causes the password to be sent in plaintext.
- CVE-2005-0127May 2, 2005risk 0.00cvss —epss 0.03
Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.
- CVE-2004-0383May 4, 2004risk 0.00cvss —epss 0.00
Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email."
- CVE-2004-0086Mar 3, 2004risk 0.00cvss —epss 0.01
Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.
- CVE-2003-0881Nov 3, 2003risk 0.00cvss —epss 0.01
Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which could allow remote attackers to gain privileges by sniffing the password.
Page 2 of 2