Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Safari HIGH 9.3
CVE-2010-1385EPSS 5%

Use-after-free vulnerability in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote att…

Fix: after 4.0.5
Fix from $1,950 2010-06-11
Java MEDIUM 6.8
CVE-2010-0538

Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 do not properly handle mediaLibImage objects, which allows re…

Patch available
Fix from $1,600 2010-05-21
Java 1.5 MEDIUM 6.8
CVE-2010-0539

Integer signedness error in the window drawing implementation in Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Updat…

Patch available
Fix from $1,600 2010-05-21
Safari HIGH 7.6
CVE-2010-1939EPSS 15%

Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popu…

Patch available
Fix from $1,950 2010-05-13
Airport Utility MEDIUM 6.8
CVE-2009-2822

AirPort Utility before 5.5.1 for Apple AirPort Base Station does not properly distribute MAC address ACLs to network extenders, which allows remote a…

Fix: after 5.4.2
Fix from $1,600 2010-04-05
Iphone Os MEDIUM 5.0
CVE-2010-1226

The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of servic…

No fix yet
Fix from $1,600 2010-04-01
Itunes MEDIUM 6.9
CVE-2010-0532

Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified fi…

Fix: after 9.0.3
Fix from $1,600 2010-03-31
Mac Os X Server HIGH 9.0
CVE-2010-0522

Server Admin in Apple Mac OS X Server 10.5.8 does not properly determine the privileges of users who had former membership in the admin group, which …

Patch available
Fix from $1,950 2010-03-30
Mac Os X HIGH 7.5
CVE-2010-0524

The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of a…

Mitigation only
Fix from $1,950 2010-03-30
Mac Os X MEDIUM 6.8
CVE-2010-0515

QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and appli…

Patch available
Fix from $1,600 2010-03-30
Mac Os X MEDIUM 6.8
CVE-2010-0516

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of servic…

Patch available
Fix from $1,600 2010-03-30
Mac Os X MEDIUM 6.8
CVE-2010-0517

Heap-based buffer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of servic…

Patch available
Fix from $1,600 2010-03-30
Mac Os X MEDIUM 6.8
CVE-2010-0518

QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and appli…

Patch available
Fix from $1,600 2010-03-30
Mac Os X MEDIUM 6.8
CVE-2010-0519EPSS 9%

Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (applica…

Patch available
Fix from $1,600 2010-03-30
Mac Os X MEDIUM 6.8
CVE-2010-0520EPSS 19%

Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code o…

Patch available
Fix from $1,600 2010-03-30
Mac Os X MEDIUM 6.5
CVE-2010-0535

Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending …

Mitigation only
Fix from $1,600 2010-03-30
Mac Os X MEDIUM 5.0
CVE-2010-0521

Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to …

Fix: after 10.6.2
Fix from $1,600 2010-03-30
Mac Os X Server MEDIUM 5.0
CVE-2010-0523

Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive informatio…

Mitigation only
Fix from $1,600 2010-03-30
Mac Os X MEDIUM 5.0
CVE-2010-0525

Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certif…

Fix: after 10.6.2
Fix from $1,600 2010-03-30
Mac Os X HIGH 10.0
CVE-2010-0055

xar in Apple Mac OS X 10.5.8 does not properly validate package signatures, which allows attackers to have an unspecified impact via a modified packa…

Patch available
Fix from $1,950 2010-03-30
Mac Os X HIGH 10.0
CVE-2010-0508

Mail in Apple Mac OS X before 10.6.3 does not disable the filter rules associated with a deleted mail account, which has unspecified impact and attac…

Fix: after 10.6.2
Fix from $1,950 2010-03-30
Mac Os X HIGH 9.3
CVE-2010-0512

The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window ac…

Patch available
Fix from $1,950 2010-03-30
Mac Os X Server HIGH 9.0
CVE-2010-0510

Password Server in Apple Mac OS X Server before 10.6.3 does not properly perform password replication, which might allow remote authenticated users t…

Fix: after 10.6.2
Fix from $1,950 2010-03-30
Mac Os X HIGH 7.8
CVE-2010-0500

Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of…

Fix: after 10.6.2
Fix from $1,950 2010-03-30
Mac Os X Server HIGH 7.5
CVE-2010-0504

Multiple stack-based buffer overflows in iChat Server in Apple Mac OS X Server before 10.6.3 allow remote attackers to execute arbitrary code or caus…

Fix: after 10.6.2
Fix from $1,950 2010-03-30
Mac Os X HIGH 7.2
CVE-2010-0498

Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local user…

Fix: after 10.6.2
Fix from $1,950 2010-03-30
Mac Os X HIGH 7.2
CVE-2010-0509

SFLServer in OS Services in Apple Mac OS X before 10.6.3 allows local users to gain privileges via vectors related to use of wheel group membership d…

Fix: after 10.6.2
Fix from $1,950 2010-03-30
Mac Os X MEDIUM 6.9
CVE-2010-0064

DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticated Finder copy, which might allow local users to b…

Patch available
Fix from $1,600 2010-03-30
Mac Os X MEDIUM 6.8
CVE-2010-0060

CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and appli…

Patch available
Fix from $1,600 2010-03-30
Mac Os X MEDIUM 6.8
CVE-2010-0062

Heap-based buffer overflow in quicktime.qts in CoreMedia and QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary c…

Patch available
Fix from $1,600 2010-03-30