Skip to main content

Vendor/product archive

apple / mac_os_x CVEs

Beta · best-effort

5,565 CVEs tagged to apple / mac_os_x1,424 Critical, 2,236 High, 1,693 Medium, 212 Low, 0 Unrated.

CVE-2006-1220

Published Mar 14, 2006

Integer overflow in the mach_msg_send function in the kernel for Mac OS X might allow local users to execute arbitrary code via unknown attack vectors related to a large message h…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0387

Published Mar 6, 2006

Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via unspecified vectors involving a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0386

Published Mar 3, 2006

FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVaul…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-0388

Published Mar 3, 2006

Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors invo…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-0389

Published Mar 3, 2006

Cross-site scripting (XSS) vulnerability in Syndication (Safari RSS) in Mac OS X 10.4 through 10.4.5 allows remote attackers to execute arbitrary JavaScript via unspecified vector…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-0391

Published Mar 3, 2006

Directory traversal vulnerability in the BOM framework in Mac OS X 10.x before 10.3.9 and 10.4 before 10.4.5 allows user-assisted attackers to overwrite or create arbitrary files…

CVSS 1.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-0383

Published Mar 2, 2006

IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "i…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0384

Published Mar 2, 2006

automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause au…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0848

Published Feb 22, 2006

The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloadin…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0382

Published Feb 14, 2006

Apple Mac OS X 10.4.5 and allows local users to cause a denial of service (crash) via an undocumented system call.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0985

Published Dec 31, 2005

Unspecified vulnerability in the Mac OS X kernel before 10.3.8 allows local users to cause a denial of service (temporary hang) via unspecified attack vectors related to the fan c…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-1726

Published Dec 31, 2005

The CoreGraphics Window Server in Mac OS X 10.4.1 allows local users with console access to gain privileges by "launching commands into root sessions."

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2194

Published Dec 31, 2005

Unspecified vulnerability in the Apple Mac OS X kernel before 10.4.2 allows remote attackers to cause a denial of service (kernel panic) via a crafted TCP packet, possibly related…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2713

Published Dec 31, 2005

passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to create arbitrary world-writable files as root by specifying an alterna…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2714

Published Dec 31, 2005

passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to overwrite arbitrary files via a symlink attack on the .pwtmp.[PID] tem…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3706

Published Dec 31, 2005

Heap-based buffer overflow in LibSystem in Mac OS X 10.4 through 10.4.5 allows context-dependent attackers to execute arbitrary code by causing an application that uses LibSystem…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3782

Published Dec 31, 2005

Mac OS X 10.4.3 up to 10.4.6, when loginwindow uses the "Name and password" setting, and the "Show the Restart, Sleep, and Shut Down buttons" option is disabled, allows users with…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-2757

Published Dec 1, 2005

Heap-based buffer overflow in CoreFoundation in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to execute arbitrary code via unknown attack vectors involving…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3700

Published Dec 1, 2005

Unknown vulnerability in iodbcadmintool in the ODBC Administrator utility in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows local users to execute arbitrary code via unknown at…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3702

Published Dec 1, 2005

Safari in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows remote attackers to cause files to be downloaded to locations outside the download directory via a long file name.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3704

Published Dec 1, 2005

System log server in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to spoof syslog messages in log files by injecting various control characters such as new…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3705

Published Dec 1, 2005

Heap-based buffer overflow in WebKit in Mac OS X and OS X Server 10.3.9 and 10.4.3, as used in applications such as Safari, allows remote attackers to execute arbitrary code via u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2739

Published Nov 1, 2005

Keychain Access in Mac OS X 10.4.2 and earlier keeps a password visible even if a keychain times out while the password is being viewed, which could allow attackers with physical…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 5,351-5,375 of 5,565 CVEsPage 215 of 223