Skip to main content

Vendor/product archive

apple / mac_os_x CVEs

Beta · best-effort

5,565 CVEs tagged to apple / mac_os_x1,424 Critical, 2,236 High, 1,693 Medium, 212 Low, 0 Unrated.

CVE-2006-1444

Published May 12, 2006

CoreGraphics in Apple Mac OS X 10.4.6, when "Enable access for assistive devices" is on, allows an application to bypass restrictions for secure event input and read certain event…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1445

Published May 12, 2006

Buffer overflow in the FTP server (FTPServer) in Apple Mac OS X 10.3.9 and 10.4.6 allows remote authenticated users to execute arbitrary code via vectors related to "FTP server pa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1446

Published May 12, 2006

Keychain in Apple Mac OS X 10.3.9 and 10.4.6 might allow an application to bypass a locked Keychain by first obtaining a reference to the Keychain when it is unlocked, then reusin…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1447

Published May 12, 2006

LaunchServices in Apple Mac OS X 10.4.6 allows remote attackers to cause Safari to launch unsafe content via long file name extensions, which prevents Download Validation from det…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1448

Published May 12, 2006

Finder in Apple Mac OS X 10.3.9 and 10.4.6 allows user-assisted attackers to execute arbitrary code by tricking a user into launching an Internet Location item that appears to use…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1449

Published May 12, 2006

Integer overflow in Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted MacMIME encapsulated attachment.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1450

Published May 12, 2006

Mail in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via an enriched text e-mail message with "invalid color information" that causes Mail to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1451

Published May 12, 2006

MySQL Manager in Apple Mac OS X 10.3.9 and 10.4.6, when setting up a new MySQL database server, does not use the "New MySQL root password" that is provided, which causes the MySQL…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1452

Published May 12, 2006

Stack-based buffer overflow in Preview in Apple Mac OS 10.4 up to 10.4.6 allows local users to execute arbitrary code via a deep directory hierarchy.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1455

Published May 12, 2006

QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to cause a denial of service (crash and connection interruption) via a QuickTime movie with…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1456

Published May 12, 2006

Buffer overflow in QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted RTSP request, which is not proper…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1457

Published May 12, 2006

Safari on Apple Mac OS X 10.4.6, when "Open `safe' files after downloading" is enabled, will automatically expand archives, which could allow remote attackers to overwrite arbitra…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-2277

Published May 10, 2006

Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial of service (application crash) via a crafted OpenEXR (.exr) image file, which t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1981

Published Apr 21, 2006

Unspecified vulnerability in Java InputMethods on Mac OS X 10.4.5 may cause InputMethods to send input events for secure fields to the wrong text field, which might reveal the pas…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1982

Published Apr 21, 2006

Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remote attackers to execute arbitr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1983

Published Apr 21, 2006

Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) PredictorVS…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1984

Published Apr 21, 2006

Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used in applications that use ImageIO or AppKit, allows remote attackers to cause a d…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0401

Published Apr 5, 2006

Unspecified vulnerability in Mac OS X before 10.4.6, when running on an Intel-based computer, allows attackers with physical access to bypass the firmware password and log on in S…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0396

Published Mar 14, 2006

Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name val…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0397

Published Mar 14, 2006

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0398

Published Mar 14, 2006

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0399

Published Mar 14, 2006

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0400

Published Mar 14, 2006

CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin policy and execute Javascript in other domains via unknown vectors involving "craft…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 5,326-5,350 of 5,565 CVEsPage 214 of 223