Vulnerability index

Browse CVEs

365 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mac Os X HIGH 7.5
CVE-2005-1933

Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget …

No fix yet
Fix from $1,950 2005-06-13
Mac Os X HIGH 7.2
CVE-2005-0972

Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.

Mitigation only
Fix from $1,950 2005-05-12
Mac Os X HIGH 7.2
CVE-2005-0974

Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.

Mitigation only
Fix from $1,950 2005-05-12
Mac Os X HIGH 7.5
CVE-2005-1332

Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files wi…

Mitigation only
Fix from $1,950 2005-05-04
Mac Os X HIGH 7.5
CVE-2005-1337

Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges vi…

Mitigation only
Fix from $1,950 2005-05-04
Mac Os X HIGH 7.5
CVE-2005-1339

lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.

Mitigation only
Fix from $1,950 2005-05-04
Mac Os X Server HIGH 7.2
CVE-2005-0594

Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.

Mitigation only
Fix from $1,950 2005-05-04
Mac Os X HIGH 7.2
CVE-2005-1335

Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper pro…

Mitigation only
Fix from $1,950 2005-05-04
Mac Os X HIGH 7.6
CVE-2005-0970

Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the intended design, which may allow atta…

Mitigation only
Fix from $1,950 2005-05-02
Safari MEDIUM 5.0
CVE-2005-0234

The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that ar…

No fix yet
Fix from $1,600 2005-05-02
Safari MEDIUM 5.0
CVE-2005-0976

AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrar…

No fix yet
Fix from $1,600 2005-05-02
Quicktime Pictureviewer MEDIUM 5.0
CVE-2005-1106

PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximu…

Mitigation only
Fix from $1,600 2005-05-02
Mac Os X HIGH 7.2
CVE-2005-0716

Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execut…

Mitigation only
Fix from $1,950 2005-03-21
Ical HIGH 7.5
CVE-2004-1021

iCal before 1.5.4 on Mac OS X 10.2.3, and other later versions, does not alert the user when handling calendars that use alarms, which allows attacke…

Mitigation only
Fix from $1,950 2005-03-01
Apple Remote Desktop HIGH 10.0
CVE-2004-0962

Apple Remote Desktop Client 1.2.4 executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application, which a…

Mitigation only
Fix from $1,950 2005-02-09
Safari HIGH 7.5
CVE-2004-1122

Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialo…

Mitigation only
Fix from $1,950 2005-01-10
Safari HIGH 7.5
CVE-2004-1314

Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but res…

Mitigation only
Fix from $1,950 2005-01-10
Safari MEDIUM 5.0
CVE-2004-1199

Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated usin…

No fix yet
Fix from $1,600 2005-01-10
Mac Os X Server MEDIUM 5.0
CVE-2004-1832

Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a denial of service (crash and restart) via a large…

Mitigation only
Fix from $1,600 2004-12-31
Mac Os X MEDIUM 5.0
CVE-2004-0743

Safari in Mac OS X before 10.3.5, after sending form data using the POST method, may re-send the data to a GET method URL if that URL is redirected a…

Mitigation only
Fix from $1,600 2004-11-23
Mac Os X MEDIUM 5.0
CVE-2004-0744

The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial of service (memory and resource consumption) via …

Mitigation only
Fix from $1,600 2004-11-23
Mac Os X HIGH 7.2
CVE-2004-0822

Buffer overflow in The Core Foundation framework (CoreFoundation.framework) in Mac OS X 10.2.8, 10.3.4, and 10.3.5 allows local users to execute arbi…

Mitigation only
Fix from $1,950 2004-09-07
Mac Os X HIGH 7.5
CVE-2004-0518

Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.

No fix yet
Fix from $1,950 2004-08-18
Mac Os X HIGH 10.0
CVE-2004-0539

The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote att…

Mitigation only
Fix from $1,950 2004-08-06
Mac Os X HIGH 7.5
CVE-2004-0538

LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary …

Mitigation only
Fix from $1,950 2004-08-06
Safari HIGH 7.5
CVE-2004-0720

Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates we…

Mitigation only
Fix from $1,950 2004-07-27
Mac Os X HIGH 7.2
CVE-2004-0382

Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration fil…

No fix yet
Fix from $1,950 2004-05-04
Mac Os X HIGH 7.2
CVE-2004-0383

Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email."

No fix yet
Fix from $1,950 2004-05-04
Safari HIGH 7.5
CVE-2003-0514EPSS 5%

Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory trav…

No fix yet
Fix from $1,950 2004-04-15
Mac Os X HIGH 10.0
CVE-2004-0168

Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."

No fix yet
Fix from $1,950 2004-03-15