Vulnerability index

Browse CVEs

56 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Safari HIGH 9.3
CVE-2010-1770

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.3…

Fix: 5.0.375.70+
Fix from $1,950 2010-06-11
Safari HIGH 9.3
CVE-2010-1415EPSS 7%

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle libxml context…

Fix: after 4.0.5
Fix from $1,950 2010-06-11
Safari HIGH 9.3
CVE-2010-1176EPSS 9%

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary…

No fix yet
Fix from $1,950 2010-03-29
Safari HIGH 9.3
CVE-2010-1177EPSS 7%

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary…

No fix yet
Fix from $1,950 2010-03-29
Safari HIGH 9.3
CVE-2010-1180EPSS 8%

Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary…

No fix yet
Fix from $1,950 2010-03-29
Safari HIGH 10.0
CVE-2010-1120EPSS 5%

Unspecified vulnerability in Safari 4 on Apple Mac OS X 10.6 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated b…

Mitigation only
Fix from $1,950 2010-03-25
Safari HIGH 9.3
CVE-2010-0043EPSS 6%

ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service …

Fix: after 4.0.4
Fix from $1,950 2010-03-15
Safari HIGH 9.3
CVE-2010-0046EPSS 6%

The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a d…

Fix: after 4.0.4
Fix from $1,950 2010-03-15
Mac Os X MEDIUM 6.8
CVE-2009-2809

ImageIO in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a…

Patch available
Fix from $1,600 2009-09-14
Mac Os X MEDIUM 6.8
CVE-2009-2811

Incomplete blacklist vulnerability in Launch Services in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code via a …

Patch available
Fix from $1,600 2009-09-14
Safari HIGH 9.3
CVE-2009-1698EPSS 8%

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during h…

Fix: after 3.2.2
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1704

CFNetwork in Apple Safari before 4.0 misinterprets downloaded image files as local HTML documents in unspecified circumstances, which allows remote a…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1712EPSS 8%

WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gai…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-0945EPSS 9%

Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPho…

Fix: after 3.2.2
Fix from $1,950 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0145EPSS 5%

CoreGraphics in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows rem…

Patch available
Fix from $1,600 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0160

QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (ap…

Patch available
Fix from $1,600 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0944

The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office fil…

Patch available
Fix from $1,600 2009-05-13
Mac Os X HIGH 9.3
CVE-2008-3638

Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary pro…

Mitigation only
Fix from $1,950 2008-09-26
Itunes HIGH 7.5
CVE-2008-3434

Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code v…

Fix: after 6.0.5
Fix from $1,950 2008-08-01
Mac Os X MEDIUM 6.8
CVE-2008-0060

Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML…

Patch available
Fix from $1,600 2008-03-18
Mail MEDIUM 6.8
CVE-2008-0039

Unspecified vulnerability in Mail in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary commands via a crafted file:// URL.

Patch available
Fix from $1,600 2008-02-12
Mac Os X MEDIUM 6.8
CVE-2008-0042

Argument injection vulnerability in Terminal.app in Terminal in Apple Mac OS X 10.4.11 and 10.5 through 10.5.1 allows remote attackers to execute arb…

Patch available
Fix from $1,600 2008-02-12
Iphoto HIGH 9.3
CVE-2008-0043

Format string vulnerability in Apple iPhoto before 7.1.2 allows remote attackers to execute arbitrary code via photocast subscriptions.

Fix: after 7.1
Fix from $1,950 2008-02-08
Mac Os X HIGH 7.5
CVE-2006-0397

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into openi…

Patch available
Fix from $1,950 2006-03-14
Mac Os X HIGH 7.5
CVE-2006-0398

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into openi…

Patch available
Fix from $1,950 2006-03-14
Mac Os X HIGH 7.5
CVE-2006-0399

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into openi…

Patch available
Fix from $1,950 2006-03-14