VYPR

OS X

by Apple Inc.

CVEs (553)

  • CVE-2014-1264Feb 27, 2014
    risk 0.00cvss epss 0.00

    Finder in Apple OS X before 10.9.2 does not ensure ACL integrity after the viewing of file ACL information, which allows local users to bypass intended access restrictions in opportunistic circumstances via standard filesystem operations on a file with a damaged ACL.

  • CVE-2014-1263Feb 27, 2014
    risk 0.00cvss epss 0.03

    curl and libcurl 7.27.0 through 7.35.0, when using the SecureTransport/Darwinssl backend, as used in in Apple OS X 10.9.x before 10.9.2, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509…

  • CVE-2014-1262Feb 27, 2014
    risk 0.00cvss epss 0.02

    Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages that trigger memory corruption.

  • CVE-2014-1261Feb 27, 2014
    risk 0.00cvss epss 0.03

    Integer signedness error in CoreText in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Unicode font.

  • CVE-2014-1260Feb 27, 2014
    risk 0.00cvss epss 0.02

    QuickLook in Apple OS X through 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document.

  • CVE-2014-1259Feb 27, 2014
    risk 0.00cvss epss 0.02

    Buffer overflow in File Bookmark in Apple OS X before 10.9.2 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted filename.

  • CVE-2014-1258Feb 27, 2014
    risk 0.00cvss epss 0.02

    Heap-based buffer overflow in CoreAnimation in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image.

  • CVE-2014-1257Feb 27, 2014
    risk 0.00cvss epss 0.00

    CFNetwork in Apple OS X through 10.8.5 does not remove session cookies upon a Safari reset action, which allows physically proximate attackers to bypass intended access restrictions by leveraging an unattended workstation.

  • CVE-2014-1256Feb 27, 2014
    risk 0.00cvss epss 0.01

    Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages.

  • CVE-2014-1255Feb 27, 2014
    risk 0.00cvss epss 0.02

    Apple Type Services (ATS) in Apple OS X before 10.9.2 does not properly validate calls to the free function, which allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages.

  • CVE-2014-1254Feb 27, 2014
    risk 0.00cvss epss 0.02

    Apple Type Services (ATS) in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Type 1 font that is embedded in a document.

  • CVE-2006-3356Jul 6, 2006
    risk 0.00cvss epss 0.01

    The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to cause a denial of service (application crash) via an invalid tag value in a TIFF image, possibly triggering a null dereference. NOTE: This is a different issue…

  • CVE-2004-1398Dec 31, 2004
    risk 0.00cvss epss 0.00

    Format string vulnerability in prelink.c in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via format string specifiers in the extension argument.

Page 28 of 28