Skip to main content

Vendor/product archive

apple / mac_os_x CVEs

Beta · best-effort

5,565 CVEs tagged to apple / mac_os_x1,424 Critical, 2,236 High, 1,693 Medium, 212 Low, 0 Unrated.

CVE-2006-3499

Published Aug 3, 2006

The dynamic linker (dyld) in Apple Mac OS X 10.3.9 allows local users to obtain sensitive information via unspecified dynamic linker options that affect the use of standard error…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-3500

Published Aug 3, 2006

The dynamic linker (dyld) in Apple Mac OS X 10.4.7 allows local users to execute arbitrary code via an "improperly handled condition" that leads to use of "dangerous paths," proba…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3501

Published Aug 3, 2006

Integer overflow in ImageIO for Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a cra…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3502

Published Aug 3, 2006

Unspecified vulnerability in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3503

Published Aug 3, 2006

Integer overflow in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed GIF im…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3504

Published Aug 3, 2006

The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context wh…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3505

Published Aug 3, 2006

WebKit in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML document that causes…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1472

Published Aug 2, 2006

Unspecified vulnerability in AFP Server in Apple Mac OS X 10.3.9 allows remote attackers to determine names of unauthorized files and folders via unknown vectors related to the se…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1473

Published Aug 2, 2006

Integer overflow in AFP Server for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3495

Published Aug 2, 2006

AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 stores reconnect keys in a world-readable file, which allows local users to obtain the keys and access files and folders of other us…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-3496

Published Aug 2, 2006

AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (crash) via an invalid AFP request that triggers an unchecked error condition.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3497

Published Aug 2, 2006

Unspecified vulnerability in the "compression state handling" in Bom for Apple Mac OS X 10.3.9 and 10.4.7 allows user-assisted attackers to cause a denial of service (application…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3498

Published Aug 2, 2006

Stack-based buffer overflow in bootpd in the DHCP component for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to execute arbitrary code via a crafted BOOTP request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-3946

Published Jul 31, 2006

WebCore in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted HTML that tri…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3356

Published Jul 6, 2006

The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to cause a denial of service (application crash) via an invalid ta…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1469

Published Jun 27, 2006

Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1470

Published Jun 27, 2006

OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1471

Published Jun 27, 2006

Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that ar…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1468

Published Jun 27, 2006

Unspecified vulnerability in Apple File Protocol (AFP) server in Apple Mac OS X 10.4 up to 10.4.6 includes the names of restricted files and folders within search results, which m…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1466

Published May 24, 2006

Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1439

Published May 12, 2006

NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under certain circumstances, which could allow other applications in the window session…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1440

Published May 12, 2006

BOM in Apple Mac OS X 10.3.9 and 10.4.6 allows attackers to overwrite arbitrary files via an archive that contains symbolic links.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1441

Published May 12, 2006

Integer overflow in CFNetwork in Apple Mac OS X 10.4.6 allows remote attackers to execute arbitrary code via crafted chunked transfer encoding.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1442

Published May 12, 2006

The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1443

Published May 12, 2006

Integer underflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving conversions…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,301-5,325 of 5,565 CVEsPage 213 of 223