Vulnerability index

Browse CVEs

390 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Mac Os X MEDIUM 5.0
CVE-2010-1379

Printer Setup in Apple Mac OS X 10.6 before 10.6.4 does not properly interpret character encoding, which allows remote attackers to cause a denial of…

Patch available
Fix from $1,600 2010-06-17
Iphone Os MEDIUM 5.0
CVE-2010-1226

The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of servic…

No fix yet
Fix from $1,600 2010-04-01
Mac Os X HIGH 7.8
CVE-2010-0500

Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of…

Fix: after 10.6.2
Fix from $1,950 2010-03-30
Safari HIGH 9.3
CVE-2010-0045

Apple Safari before 4.0.5 on Windows does not properly validate external URL schemes, which allows remote attackers to open local files and execute a…

Fix: after 4.0.4
Fix from $1,950 2010-03-15
Safari MEDIUM 5.8
CVE-2009-2420

Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitrary files or cause a denial of…

Mitigation only
Fix from $1,600 2009-07-09
Safari MEDIUM 5.0
CVE-2009-2421

The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a denial of service (NULL poin…

Mitigation only
Fix from $1,600 2009-07-09
Iphone Os HIGH 7.1
CVE-2009-0959

The MPEG-4 video codec in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial …

Patch available
Fix from $1,950 2009-06-19
Safari HIGH 9.3
CVE-2009-1686EPSS 8%

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle constant (aka…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Mac Os X HIGH 7.2
CVE-2008-1517

Array index error in the xnu (Mach) kernel in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (s…

Patch available
Fix from $1,950 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0942

Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) are located in a registered he…

Patch available
Fix from $1,600 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0943

Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows …

Patch available
Fix from $1,600 2009-05-13
Mac Os X MEDIUM 6.4
CVE-2009-0161

The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate…

Patch available
Fix from $1,600 2009-05-13
Cups MEDIUM 6.4
CVE-2009-0164

The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to co…

Fix: after 1.3.9
Fix from $1,600 2009-04-24
Itunes MEDIUM 5.0
CVE-2009-0016

Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) me…

Fix: after 8.0
Fix from $1,600 2009-03-14
Safari MEDIUM 5.0
CVE-2009-0744EPSS 7%

Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a feeds: U…

No fix yet
Fix from $1,600 2009-02-27
Safari HIGH 10.0
CVE-2009-0137

Multiple unspecified vulnerabilities in Safari RSS in Apple Mac OS X 10.4.11 and 10.5.6, and Windows XP and Vista, allow remote attackers to execute …

Patch available
Fix from $1,950 2009-02-13
Quicktime Mpeg 2 Playback Component HIGH 7.6
CVE-2009-0008

Unspecified vulnerability in Apple QuickTime MPEG-2 Playback Component before 7.60.92.0 on Windows allows remote attackers to cause a denial of servi…

Mitigation only
Fix from $1,950 2009-01-22
Mac Os X HIGH 7.1
CVE-2008-4224

UDF in Apple Mac OS X before 10.5.6 allows user-assisted attackers to cause a denial of service (system crash) via a malformed UDF volume in a crafte…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Bonjour MEDIUM 5.0
CVE-2008-2326EPSS 7%

mDNSResponder in the Bonjour Namespace Provider in Apple Bonjour for Windows before 1.0.5 allows attackers to cause a denial of service (NULL pointer…

Patch available
Fix from $1,600 2008-09-11
Mac Os X HIGH 10.0
CVE-2008-1030

Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent atta…

Mitigation only
Fix from $1,950 2008-06-02
Mac Os X HIGH 9.3
CVE-2008-1028

Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial o…

Mitigation only
Fix from $1,950 2008-06-02
Mac Os X HIGH 7.1
CVE-2008-0999

Apple Mac OS X 10.5.2 allows user-assisted attackers to cause a denial of service (crash) via a crafted Universal Disc Format (UDF) disk image, which…

Patch available
Fix from $1,950 2008-03-18
Mac Os X MEDIUM 6.4
CVE-2008-0054

Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelecto…

Patch available
Fix from $1,600 2008-03-18
Iphoto HIGH 7.5
CVE-2008-0830

The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: U…

No fix yet
Fix from $1,950 2008-02-19
Mac Os X HIGH 9.3
CVE-2007-6165EPSS 45%

Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an a…

No fix yet
Fix from $1,950 2007-11-29
Safari MEDIUM 6.8
CVE-2007-4671

Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows…

Fix: after 3.0.3
Fix from $1,600 2007-09-27
Iphone HIGH 7.5
CVE-2007-3753

Apple iPhone 1.1.1, with Bluetooth enabled, allows physically proximate attackers to cause a denial of service (application termination) and execute …

Patch available
Fix from $1,950 2007-09-27
Safari MEDIUM 6.8
CVE-2007-2408

WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable Java" setting, which allows remote attackers to ex…

Patch available
Fix from $1,600 2007-08-03
Mac Os X MEDIUM 6.8
CVE-2007-0197EPSS 8%

Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a l…

No fix yet
Fix from $1,600 2007-01-11
Preview MEDIUM 6.8
CVE-2007-0102

The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including deni…

Patch available
Fix from $1,600 2007-01-09