Vulnerability index

Browse CVEs

52 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Iphone Os MEDIUM 6.8
CVE-2014-1295

Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.…

Fix: after 7.1
Fix from $1,600 2014-04-23
Mac Os X MEDIUM 6.6
CVE-2013-5163

Directory Services in Apple Mac OS X before 10.8.5 Supplemental Update allows local users to bypass password-based authentication and modify arbitrar…

Fix: after 10.8.5
Fix from $1,600 2013-10-04
Mac Os X MEDIUM 5.0
CVE-2012-3721

Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Device Management private interface, which allows at…

Fix: after 10.7.4
Fix from $1,600 2012-09-20
Mac Os X HIGH 7.2
CVE-2011-3463

WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by levera…

Mitigation only
Fix from $1,950 2012-02-02
Mac Os X MEDIUM 6.8
CVE-2010-1820

Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle errors, which allows remote attackers to bypass t…

Patch available
Fix from $1,600 2010-09-21
Libsecurity MEDIUM 6.4
CVE-2010-1802

libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-…

Patch available
Fix from $1,600 2010-08-25
Mac Os X HIGH 7.2
CVE-2010-1375

NetAuthSysAgent in Network Authorization in Apple Mac OS X 10.5.8 does not have the expected authorization requirements, which allows local users to …

Patch available
Fix from $1,950 2010-06-17
Mac Os X MEDIUM 5.0
CVE-2010-0521

Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to …

Fix: after 10.6.2
Fix from $1,600 2010-03-30
Mac Os X HIGH 7.2
CVE-2010-0498

Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local user…

Fix: after 10.6.2
Fix from $1,950 2010-03-30
Safari MEDIUM 6.8
CVE-2009-2058

Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a p…

Fix: after 3.2.2
Fix from $1,600 2009-06-15
Safari MEDIUM 6.8
CVE-2009-2062

Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execut…

Fix: after 3.2.1
Fix from $1,600 2009-06-15
Safari MEDIUM 6.8
CVE-2009-2066

Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute ar…

Fix: after 3.2.1
Fix from $1,600 2009-06-15
Safari MEDIUM 5.4
CVE-2009-2072

Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to s…

Fix: after 3.2.1
Fix from $1,600 2009-06-15
Mac Os X HIGH 10.0
CVE-2009-0138

servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify t…

Patch available
Fix from $1,950 2009-02-13
Mac Os X Server HIGH 10.0
CVE-2008-4223EPSS 5%

Podcast Producer in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to bypass authentication and gain administrative access via unspecified…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Mac Os X HIGH 7.6
CVE-2008-3610

Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password a…

Patch available
Fix from $1,950 2008-09-16
Mac Os X MEDIUM 6.3
CVE-2008-3611

Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, whic…

Patch available
Fix from $1,600 2008-09-16
Mac Os X MEDIUM 6.4
CVE-2007-5855

Mail in Apple Mac OS X 10.4.11 and 10.5.1, when an SMTP account has been set up using Account Assistant, can use plaintext authentication even when M…

Mitigation only
Fix from $1,600 2007-12-19
Mac Os X HIGH 9.4
CVE-2007-5862

Java in Mac OS X 10.4 through 10.4.11 allows remote attackers to bypass Keychain access controls and add or delete arbitrary Keychain items via a cra…

Patch available
Fix from $1,950 2007-12-18
Mac Os X HIGH 7.2
CVE-2007-4693

The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen …

Patch available
Fix from $1,950 2007-11-15
Mac Os X MEDIUM 6.8
CVE-2007-4680

CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted S…

Patch available
Fix from $1,600 2007-11-15
Mac Os X HIGH 7.2
CVE-2007-3184

Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System P…

Patch available
Fix from $1,950 2007-06-12