Vulnerability index

Browse CVEs

365 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Safari HIGH 7.1
CVE-2007-2398

Apple Safari 3.0.1 beta (522.12.12) on Windows allows remote attackers to modify the window title and address bar while filling the main window with …

Mitigation only
Fix from $1,950 2007-06-21
Safari HIGH 7.8
CVE-2007-3284

corefoundation.dll in Apple Safari 3.0.1 (552.12.2) for Windows allows remote attackers to cause a denial of service (crash) via certain forms that t…

No fix yet
Fix from $1,950 2007-06-19
Safari HIGH 9.3
CVE-2007-3186

Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, …

Mitigation only
Fix from $1,950 2007-06-12
Safari HIGH 7.8
CVE-2007-3185

Apple Safari Beta 3.0.1 for Windows public beta allows remote attackers to cause a denial of service (crash) via unspecified DHTML manipulations that…

Mitigation only
Fix from $1,950 2007-06-12
Safari HIGH 7.5
CVE-2007-3187

Multiple unspecified vulnerabilities in Apple Safari for Windows allow remote attackers to cause a denial of service or execute arbitrary code, possi…

No fix yet
Fix from $1,950 2007-06-12
Mac Os X HIGH 10.0
CVE-2007-2390EPSS 9%

Buffer overflow in iChat in Apple Mac OS X 10.3.9 and 10.4.9 allows remote attackers to cause a denial of service (application termination) and possi…

Mitigation only
Fix from $1,950 2007-05-24
Mac Os X HIGH 9.4
CVE-2007-2386EPSS 50%

Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) o…

Mitigation only
Fix from $1,950 2007-05-24
Mac Os X HIGH 9.3
CVE-2007-0750

Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application …

Mitigation only
Fix from $1,950 2007-05-24
Mac Os X HIGH 7.2
CVE-2007-0752

The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, w…

Mitigation only
Fix from $1,950 2007-05-24
Mac Os X HIGH 7.2
CVE-2007-0753

Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i para…

Mitigation only
Fix from $1,950 2007-05-24
Mac Os X MEDIUM 6.8
CVE-2007-0740

Alias Manager in Apple Mac OS X 10.3.9 and 10.4.9 does not display files with the same name in mounted disk images that have the same name, which mig…

Mitigation only
Fix from $1,600 2007-05-24
Safari HIGH 10.0
CVE-2007-2843

Cross-domain vulnerability in Apple Safari 2.0.4 allows remote attackers to access restricted information from other domains via Javascript, as demon…

No fix yet
Fix from $1,950 2007-05-24
Safari HIGH 7.6
CVE-2007-2175EPSS 84%

Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2007-04-24
Mac Os X HIGH 7.2
CVE-2007-0725

Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, when running on hardware with the original AirPort w…

Mitigation only
Fix from $1,950 2007-04-24
Mac Os X HIGH 7.2
CVE-2007-0732

Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via un…

Mitigation only
Fix from $1,950 2007-04-24
Safari MEDIUM 5.0
CVE-2007-2163

Apple Safari allows remote attackers to cause a denial of service (browser crash) via JavaScript that matches a regular expression against a long str…

Mitigation only
Fix from $1,600 2007-04-22
Airport Extreme HIGH 7.5
CVE-2007-1338

The default configuration of the AirPort utility in Apple AirPort Extreme creates an IPv6 tunnel but does not enable the "Block incoming IPv6 connect…

No fix yet
Fix from $1,950 2007-03-08
Mac Os X HIGH 7.8
CVE-2007-1071EPSS 18%

Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (segmentatio…

No fix yet
Fix from $1,950 2007-02-22
Safari HIGH 7.1
CVE-2007-0644

Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format strin…

Mitigation only
Fix from $1,950 2007-02-01
Safari HIGH 7.1
CVE-2007-0646EPSS 10%

Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a d…

No fix yet
Fix from $1,950 2007-02-01
Mac Os X HIGH 7.1
CVE-2007-0647

Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifi…

No fix yet
Fix from $1,950 2007-02-01
Iphoto MEDIUM 6.8
CVE-2007-0645

Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers i…

Mitigation only
Fix from $1,600 2007-02-01
Ichat HIGH 7.8
CVE-2007-0614EPSS 8%

The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a…

No fix yet
Fix from $1,950 2007-01-31
Ichat MEDIUM 5.0
CVE-2007-0613EPSS 7%

The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entri…

No fix yet
Fix from $1,600 2007-01-31
Mac Os X MEDIUM 6.2
CVE-2007-0467

crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on applica…

No fix yet
Fix from $1,600 2007-01-31
Installer HIGH 7.6
CVE-2007-0465EPSS 18%

Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format st…

No fix yet
Fix from $1,950 2007-01-31
Quicktime HIGH 7.1
CVE-2007-0588EPSS 6%

The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote a…

Mitigation only
Fix from $1,950 2007-01-30
Software Update MEDIUM 5.0
CVE-2007-0463EPSS 18%

Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash…

No fix yet
Fix from $1,600 2007-01-29
Quicktime HIGH 10.0
CVE-2007-0462EPSS 7%

The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote at…

Mitigation only
Fix from $1,950 2007-01-26
Mac Os X MEDIUM 6.9
CVE-2007-0023

The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows loc…

No fix yet
Fix from $1,600 2007-01-24