Vulnerability index

Browse CVEs

157 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Mac Os X HIGH 7.6
CVE-2011-1516

The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all crea…

No fix yet
Fix from $1,950 2011-11-15
Mac Os X MEDIUM 6.5
CVE-2011-3436

Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allo…

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 6.8
CVE-2011-3226

Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypas…

Mitigation only
Fix from $1,600 2011-10-14
Safari MEDIUM 6.8
CVE-2011-3230EPSS 50%

Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via…

Fix: after 5.1
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 5.0
CVE-2011-3225

The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-…

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X HIGH 7.6
CVE-2011-3213

The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for a…

Fix: after 10.7.1
Fix from $1,950 2011-10-14
Safari MEDIUM 5.8
CVE-2008-7296

Apple Safari cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite o…

Patch available
Fix from $1,600 2011-08-09
Safari MEDIUM 5.8
CVE-2011-0219

Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the rendering of text from arbitrary web sites, via a …

Fix: after 5.0.5
Fix from $1,600 2011-07-21
Iphone Os HIGH 7.2
CVE-2011-0227

The queueing primitives in IOMobileFrameBuffer in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 do not properly perform type conversion, which allows…

Fix: after 4.2.8
Fix from $1,950 2011-07-19
Mac Os X HIGH 7.1
CVE-2011-2601

The GPU support functionality in Mac OS X does not properly restrict rendering time, which allows remote attackers to cause a denial of service (desk…

No fix yet
Fix from $1,950 2011-06-30
Safari MEDIUM 5.8
CVE-2011-0166

The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy a…

Fix: after 5.0.3
Fix from $1,600 2011-03-11
Iphone Os HIGH 7.2
CVE-2010-3830

Networking in Apple iOS before 4.2 accesses an invalid pointer during the processing of packet filter rules, which allows local users to gain privile…

Fix: after 4.1
Fix from $1,950 2010-11-26
Iphone Os MEDIUM 5.8
CVE-2010-3829

WebKit in Apple iOS before 4.2 allows remote attackers to bypass the remote image loading setting in Mail via an HTML LINK element with a DNS prefetc…

Fix: after 4.1
Fix from $1,600 2010-11-26
Safari MEDIUM 5.8
CVE-2010-3813

The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 t…

Fix: after 5.0.2
Fix from $1,600 2010-11-22
Mac Os X Server MEDIUM 6.8
CVE-2010-3783

Password Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly perform replication, which allows remote authenticated users to b…

Patch available
Fix from $1,600 2010-11-16
Safari MEDIUM 6.9
CVE-2010-1805

Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 on Windows allows local users to gain privileges via a Troj…

Patch available
Fix from $1,600 2010-09-10
Webkit HIGH 10.0
CVE-2010-1386

page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has un…

Mitigation only
Fix from $1,950 2010-08-19
Iphone Os MEDIUM 6.9
CVE-2010-2973

Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privil…

No fix yet
Fix from $1,600 2010-08-05
Iphone Os MEDIUM 6.9
CVE-2010-1754

Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch does not properly handle alert-based unlocks in conjunction with subsequent Remote L…

Fix: 4.0+
Fix from $1,600 2010-06-22
Iphone Os MEDIUM 6.4
CVE-2010-1757

WebKit in Apple iOS before 4 on the iPhone and iPod touch does not enforce the expected boundary restrictions on content display by an IFRAME element…

Fix: 4.0+
Fix from $1,600 2010-06-22
Iphone Os MEDIUM 5.0
CVE-2010-1751

Application Sandbox in Apple iOS before 4 on the iPhone and iPod touch does not prevent photo-library access, which might allow remote attackers to o…

Fix: 4.0+
Fix from $1,600 2010-06-22
Cups MEDIUM 6.8
CVE-2010-0542

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain cal…

Fix: after 1.4.3
Fix from $1,600 2010-06-21
Airport Utility MEDIUM 6.8
CVE-2009-2822

AirPort Utility before 5.5.1 for Apple AirPort Base Station does not properly distribute MAC address ACLs to network extenders, which allows remote a…

Fix: after 5.4.2
Fix from $1,600 2010-04-05
Mac Os X Server HIGH 9.0
CVE-2010-0522

Server Admin in Apple Mac OS X Server 10.5.8 does not properly determine the privileges of users who had former membership in the admin group, which …

Patch available
Fix from $1,950 2010-03-30
Mac Os X HIGH 7.5
CVE-2010-0524

The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of a…

Mitigation only
Fix from $1,950 2010-03-30
Mac Os X MEDIUM 6.5
CVE-2010-0535

Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending …

Mitigation only
Fix from $1,600 2010-03-30
Mac Os X HIGH 9.3
CVE-2010-0512

The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window ac…

Patch available
Fix from $1,950 2010-03-30
Mac Os X HIGH 7.2
CVE-2010-0509

SFLServer in OS Services in Apple Mac OS X before 10.6.3 allows local users to gain privileges via vectors related to use of wheel group membership d…

Fix: after 10.6.2
Fix from $1,950 2010-03-30
Mac Os X MEDIUM 6.9
CVE-2010-0064

DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticated Finder copy, which might allow local users to b…

Patch available
Fix from $1,600 2010-03-30
Mac Os X Server MEDIUM 5.0
CVE-2010-0511

Podcast Producer in Apple Mac OS X 10.6 before 10.6.3 deletes the access restrictions of a Podcast Composer workflow when this workflow is overwritte…

Patch available
Fix from $1,600 2010-03-30