Vulnerability index

Browse CVEs

157 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Mac Os X HIGH 7.5
CVE-2010-0057

AFP Server in Apple Mac OS X before 10.6.3 does not prevent guest use of AFP shares when guest access is disabled, which allows remote attackers to b…

Fix: after 10.6.2
Fix from $1,950 2010-03-30
Mac Os X MEDIUM 6.4
CVE-2009-2801

The Application Firewall in Apple Mac OS X 10.5.8 drops unspecified firewall rules after a reboot, which might allow remote attackers to bypass inten…

Patch available
Fix from $1,600 2010-03-30
Safari MEDIUM 5.0
CVE-2010-1099

Integer overflow in Apple Safari allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside t…

Mitigation only
Fix from $1,600 2010-03-24
Airport Express MEDIUM 5.0
CVE-2010-0962

The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specifie…

No fix yet
Fix from $1,600 2010-03-10
Cups MEDIUM 6.9
CVE-2010-0393

The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine t…

Mitigation only
Fix from $1,600 2010-03-05
Mac Os X Server MEDIUM 5.0
CVE-2009-2818

Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH login attempts, which makes it easier for remote …

Fix: after 10.6.1
Fix from $1,600 2009-11-10
Safari HIGH 7.2
CVE-2009-2027

The Installer in Apple Safari before 4.0 on Windows allows local users to gain privileges by checking a box that specifies an immediate launch of the…

Fix: after 3.2.3
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1600

Apple Safari executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF…

Mitigation only
Fix from $1,950 2009-05-11
Mac Os X HIGH 7.2
CVE-2009-1235

XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, w…

Fix: after 10.5.6
Fix from $1,950 2009-04-02
Mac Os X HIGH 7.2
CVE-2009-0011

Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via unknown vectors related to an "insecure file opera…

Patch available
Fix from $1,950 2009-02-13
Mac Os X HIGH 9.3
CVE-2008-4234

Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers …

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Mac Os X Server HIGH 7.5
CVE-2008-4215

Weblog in Mac OS X Server 10.4.11 does not properly check an error condition when a weblog posting access control list is specified for a user that h…

Patch available
Fix from $1,950 2008-10-10
Mac Os X HIGH 9.0
CVE-2008-3618

The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their …

Patch available
Fix from $1,950 2008-09-16
Mac Os X HIGH 7.2
CVE-2008-3609

The kernel in Apple Mac OS X 10.5 through 10.5.4 does not properly flush cached credentials during recycling (aka purging) of a vnode, which might al…

Patch available
Fix from $1,950 2008-09-16
Mac Os X MEDIUM 5.0
CVE-2008-2331

Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Info window after a lock operation that modifies Sha…

Patch available
Fix from $1,600 2008-09-16
Ipod Touch HIGH 7.1
CVE-2008-3631

Application Sandbox in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, does not properly isolate third-party applications, which al…

Mitigation only
Fix from $1,950 2008-09-11
Safari MEDIUM 6.8
CVE-2008-3170

Apple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which could allow remote attackers to …

Mitigation only
Fix from $1,600 2008-07-14
Mac Os X MEDIUM 6.8
CVE-2008-2309

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a…

Patch available
Fix from $1,600 2008-07-01
Safari HIGH 9.3
CVE-2008-2306

Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows re…

Fix: after 3.1.1
Fix from $1,950 2008-06-23
Mac Os X HIGH 7.2
CVE-2008-2830

Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of sc…

No fix yet
Fix from $1,950 2008-06-23
Safari HIGH 9.3
CVE-2008-2540EPSS 8%

Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, w…

Fix: 3.1.2+
Fix from $1,950 2008-06-03
Mac Os X MEDIUM 6.9
CVE-2008-0998

Unspecified vulnerability in NetCfgTool in the System Configuration component in Apple Mac OS X 10.4.11 and 10.5.2 allows local users to bypass autho…

Patch available
Fix from $1,600 2008-03-18
Mac Os X HIGH 7.1
CVE-2008-0045

Unspecified vulnerability in AFP Server in Apple Mac OS X 10.4.11 allows remote attackers to bypass cross-realm authentication via unknown manipulati…

Patch available
Fix from $1,950 2008-03-18
Mac Os X MEDIUM 5.0
CVE-2008-0046

The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the "Set access for specific services and applications" rad…

Patch available
Fix from $1,600 2008-03-18
Mac Os X HIGH 9.4
CVE-2007-5856

Quick Look Apple Mac OS X 10.5.1, when previewing an HTML file, does not prevent plug-ins from making network requests, which might allow remote atta…

Mitigation only
Fix from $1,950 2007-12-19
Mac Os X MEDIUM 6.4
CVE-2007-5857

Quick Look in Apple Mac OS X 10.5.1 does not prevent a movie from accessing URLs when the movie file is previewed or if an icon is created, which mig…

Mitigation only
Fix from $1,600 2007-12-19
Mac Os X HIGH 9.3
CVE-2007-6165EPSS 45%

Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an a…

No fix yet
Fix from $1,950 2007-11-29
Safari HIGH 7.5
CVE-2007-4699

The default configuration of Safari in Apple Mac OS X 10.4 through 10.4.10 adds a private key to the keychain with permissions that allow other appli…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 7.5
CVE-2007-4700

Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to use Safari as an indirect proxy and send attack…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 10.0
CVE-2007-4691

The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that allow attackers to bypass intended restrictions f…

Patch available
Fix from $1,950 2007-11-15