Skip to main content

Vendor/product archive

apple / mac_os_x_server CVEs

Beta · best-effort

817 CVEs tagged to apple / mac_os_x_server163 Critical, 161 High, 430 Medium, 63 Low, 0 Unrated.

CVE-2006-3504

Published Aug 3, 2006

The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context wh…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3505

Published Aug 3, 2006

WebKit in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML document that causes…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1472

Published Aug 2, 2006

Unspecified vulnerability in AFP Server in Apple Mac OS X 10.3.9 allows remote attackers to determine names of unauthorized files and folders via unknown vectors related to the se…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1473

Published Aug 2, 2006

Integer overflow in AFP Server for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3495

Published Aug 2, 2006

AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 stores reconnect keys in a world-readable file, which allows local users to obtain the keys and access files and folders of other us…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-3496

Published Aug 2, 2006

AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (crash) via an invalid AFP request that triggers an unchecked error condition.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3497

Published Aug 2, 2006

Unspecified vulnerability in the "compression state handling" in Bom for Apple Mac OS X 10.3.9 and 10.4.7 allows user-assisted attackers to cause a denial of service (application…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3498

Published Aug 2, 2006

Stack-based buffer overflow in bootpd in the DHCP component for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to execute arbitrary code via a crafted BOOTP request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-3356

Published Jul 6, 2006

The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to cause a denial of service (application crash) via an invalid ta…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1469

Published Jun 27, 2006

Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1470

Published Jun 27, 2006

OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1471

Published Jun 27, 2006

Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that ar…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1455

Published May 12, 2006

QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to cause a denial of service (crash and connection interruption) via a QuickTime movie with…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1456

Published May 12, 2006

Buffer overflow in QuickTime Streaming Server in Apple Mac OS X 10.3.9 and 10.4.6 allows remote attackers to execute arbitrary code via a crafted RTSP request, which is not proper…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1457

Published May 12, 2006

Safari on Apple Mac OS X 10.4.6, when "Open `safe' files after downloading" is enabled, will automatically expand archives, which could allow remote attackers to overwrite arbitra…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1981

Published Apr 21, 2006

Unspecified vulnerability in Java InputMethods on Mac OS X 10.4.5 may cause InputMethods to send input events for secure fields to the wrong text field, which might reveal the pas…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1982

Published Apr 21, 2006

Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remote attackers to execute arbitr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1983

Published Apr 21, 2006

Multiple heap-based buffer overflows in Mac OS X 10.4.6 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) PredictorVS…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1984

Published Apr 21, 2006

Unspecified vulnerability in the _cg_TIFFSetField function in Mac OS X 10.4.6 and earlier, as used in applications that use ImageIO or AppKit, allows remote attackers to cause a d…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0401

Published Apr 5, 2006

Unspecified vulnerability in Mac OS X before 10.4.6, when running on an Intel-based computer, allows attackers with physical access to bypass the firmware password and log on in S…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0396

Published Mar 14, 2006

Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name val…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0397

Published Mar 14, 2006

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0398

Published Mar 14, 2006

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into opening an application that appears…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 651-675 of 817 CVEsPage 27 of 33