Skip to main content

Vendor archive

apple CVEs

Beta · best-effort

14,941 CVEs tagged to vendor apple2,405 Critical, 6,151 High, 5,654 Medium, 731 Low, 0 Unrated.

CVE-2001-0649

Published Sep 20, 2001

Personal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-1446

Published Sep 11, 2001

Find-By-Content in Mac OS X 10.0 through 10.0.4 creates world-readable index files named .FBCIndex in every directory, which allows remote attackers to learn the contents of files…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0198

Published May 3, 2001

Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0068

Published Feb 12, 2001

Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-0102

Published Feb 12, 2001

"Multiple Users" Control Panel in Mac OS 9 allows Normal users to gain Owner privileges by removing the Users & Groups Data File, which effectively removes the Owner password and…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0563

Published Oct 20, 2000

The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrar…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2000-0346

Published May 2, 2000

AppleShare IP 6.1 and later allows a remote attacker to read potentially sensitive information via an invalid range request to the web server.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0299

Published Apr 4, 2000

Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-1102

Published Dec 31, 1999

lpr on SunOS 4.1.1, BSD 4.3, A/UX 2.0.1, and other BSD-based operating systems allows local users to create or overwrite arbitrary files via a symlink attack that is triggered aft…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2000-0041

Published Dec 28, 1999

Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-1077

Published Nov 1, 1999

Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-1076

Published Oct 26, 1999

Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the "Log Out" option and selecting a "Cancel" option in the di…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-1543

Published Jul 10, 1999

MacOS uses weak encryption for passwords that are stored in the Users & Groups Data File.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-1412

Published Jun 3, 1999

A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CG…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-1393

Published May 21, 1999

Control Panel "Password Security" option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup d…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 14,926-14,941 of 14,941 CVEsPage 598 of 598