Vulnerability index

Browse CVEs

365 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2005-1933 Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget … Mac Os X No fix yet Fix from $1,9502005-06-13 HIGH 7.2 CVE-2005-0972 Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters. Mac Os X Mitigation only Fix from $1,9502005-05-12 HIGH 7.2 CVE-2005-0974 Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments. Mac Os X Mitigation only Fix from $1,9502005-05-12 HIGH 7.5 CVE-2005-1332 Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files wi… Mac Os X Mitigation only Fix from $1,9502005-05-04 HIGH 7.5 CVE-2005-1337 Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges vi… Mac Os X Mitigation only Fix from $1,9502005-05-04 HIGH 7.5 CVE-2005-1339 lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name. Mac Os X Mitigation only Fix from $1,9502005-05-04 HIGH 7.2 CVE-2005-0594 Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code. Mac Os X Server Mitigation only Fix from $1,9502005-05-04 HIGH 7.2 CVE-2005-1335 Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper pro… Mac Os X Mitigation only Fix from $1,9502005-05-04 HIGH 7.6 CVE-2005-0970 Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the intended design, which may allow atta… Mac Os X Mitigation only Fix from $1,9502005-05-02 MEDIUM 5.0 CVE-2005-0234 The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that ar… Safari No fix yet Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-0976 AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrar… Safari No fix yet Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-1106 PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximu… Quicktime Pictureviewer Mitigation only Fix from $1,6002005-05-02 HIGH 7.2 CVE-2005-0716 Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execut… Mac Os X Mitigation only Fix from $1,9502005-03-21 HIGH 7.5 CVE-2004-1021 iCal before 1.5.4 on Mac OS X 10.2.3, and other later versions, does not alert the user when handling calendars that use alarms, which allows attacke… Ical Mitigation only Fix from $1,9502005-03-01 HIGH 10.0 CVE-2004-0962 Apple Remote Desktop Client 1.2.4 executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application, which a… Apple Remote Desktop Mitigation only Fix from $1,9502005-02-09 HIGH 7.5 CVE-2004-1122 Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialo… Safari Mitigation only Fix from $1,9502005-01-10 HIGH 7.5 CVE-2004-1314 Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but res… Safari Mitigation only Fix from $1,9502005-01-10 MEDIUM 5.0 CVE-2004-1199 Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated usin… Safari No fix yet Fix from $1,6002005-01-10 MEDIUM 5.0 CVE-2004-1832 Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a denial of service (crash and restart) via a large… Mac Os X Server Mitigation only Fix from $1,6002004-12-31 MEDIUM 5.0 CVE-2004-0743 Safari in Mac OS X before 10.3.5, after sending form data using the POST method, may re-send the data to a GET method URL if that URL is redirected a… Mac Os X Mitigation only Fix from $1,6002004-11-23 MEDIUM 5.0 CVE-2004-0744 The TCP/IP Networking component in Mac OS X before 10.3.5 allows remote attackers to cause a denial of service (memory and resource consumption) via … Mac Os X Mitigation only Fix from $1,6002004-11-23 HIGH 7.2 CVE-2004-0822 Buffer overflow in The Core Foundation framework (CoreFoundation.framework) in Mac OS X 10.2.8, 10.3.4, and 10.3.5 allows local users to execute arbi… Mac Os X Mitigation only Fix from $1,9502004-09-07 HIGH 7.5 CVE-2004-0518 Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors. Mac Os X No fix yet Fix from $1,9502004-08-18 HIGH 10.0 CVE-2004-0539 The "Show in Finder" button in the Safari web browser in Mac OS X 10.3.4 and 10.2.8 may execute downloaded applications, which could allow remote att… Mac Os X Mitigation only Fix from $1,9502004-08-06 HIGH 7.5 CVE-2004-0538 LaunchServices in Mac OS X 10.3.4 and 10.2.8 automatically registers and executes new applications, which could allow attackers to execute arbitrary … Mac Os X Mitigation only Fix from $1,9502004-08-06 HIGH 7.5 CVE-2004-0720 Safari 1.2.2 does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates we… Safari Mitigation only Fix from $1,9502004-07-27 HIGH 7.2 CVE-2004-0382 Unknown vulnerability in the CUPS printing system in Mac OS X 10.3.3 and Mac OS X 10.2.8 with unknown impact, possibly related to a configuration fil… Mac Os X No fix yet Fix from $1,9502004-05-04 HIGH 7.2 CVE-2004-0383 Unknown vulnerability in Mail for Mac OS X 10.3.3 and 10.2.8, with unknown impact, related to "the handling of HTML-formatted email." Mac Os X No fix yet Fix from $1,9502004-05-04 HIGH 7.5 CVE-2003-0514EPSS 5% Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory trav… Safari No fix yet Fix from $1,9502004-04-15 HIGH 10.0 CVE-2004-0168 Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging." Mac Os X No fix yet Fix from $1,9502004-03-15