Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X MEDIUM 6.2
CVE-2009-2836

Race condition in Login Window in Apple Mac OS X 10.6.x before 10.6.2, when at least one account has a blank password, allows attackers to bypass pas…

Patch available
Fix from $1,600 2009-11-10
Mac Os X MEDIUM 5.8
CVE-2009-2831

Dictionary in Apple Mac OS X 10.5.8 allows remote attackers to create arbitrary files with any contents, and thereby execute arbitrary code, via craf…

Patch available
Fix from $1,600 2009-11-10
Mac Os X MEDIUM 5.4
CVE-2009-2808

Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help content from a web site, which allows man-in-the-…

Fix: after 10.6.1
Fix from $1,600 2009-11-10
Mac Os X Server MEDIUM 5.1
CVE-2009-2832

Buffer overflow in FTP Server in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (daemon …

Fix: after 10.6.1
Fix from $1,600 2009-11-10
Mac Os X Server MEDIUM 5.0
CVE-2009-2818

Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH login attempts, which makes it easier for remote …

Fix: after 10.6.1
Fix from $1,600 2009-11-10
Mac Os X Server MEDIUM 5.0
CVE-2009-2829

Event Monitor in Apple Mac OS X 10.5.8 does not properly handle crafted authentication data sent to an SSH daemon, which allows remote attackers to c…

Patch available
Fix from $1,600 2009-11-10
Safari HIGH 7.5
CVE-2009-3455

Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field o…

Fix: after 4.0.2
Fix from $1,950 2009-09-29
Itunes HIGH 9.3
CVE-2009-2817EPSS 9%

Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a…

Fix: after 9.0
Fix from $1,950 2009-09-24
Iphone Os HIGH 7.5
CVE-2009-3273

iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof…

Mitigation only
Fix from $1,950 2009-09-21
Safari MEDIUM 5.0
CVE-2009-3272EPSS 6%

Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to c…

No fix yet
Fix from $1,600 2009-09-21
Mac Os X HIGH 7.2
CVE-2009-2807

Heap-based buffer overflow in the USB backend in CUPS in Apple Mac OS X 10.5.8 allows local users to gain privileges via unspecified vectors.

Patch available
Fix from $1,950 2009-09-14
Mac Os X MEDIUM 6.8
CVE-2009-2803

CarbonCore in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (memory corruption and applic…

Patch available
Fix from $1,600 2009-09-14
Safari MEDIUM 6.8
CVE-2009-2804

Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary …

Fix: after 4.0.3
Fix from $1,600 2009-09-14
Mac Os X MEDIUM 6.8
CVE-2009-2805

Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service …

Patch available
Fix from $1,600 2009-09-14
Mac Os X MEDIUM 6.8
CVE-2009-2809

ImageIO in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a…

Patch available
Fix from $1,600 2009-09-14
Mac Os X MEDIUM 6.8
CVE-2009-2811

Incomplete blacklist vulnerability in Launch Services in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code via a …

Patch available
Fix from $1,600 2009-09-14
Mac Os X MEDIUM 6.8
CVE-2009-2812

Launch Services in Apple Mac OS X 10.5.8 does not properly recognize an unsafe Uniform Type Identifier (UTI) in an exported document type in a downlo…

Patch available
Fix from $1,600 2009-09-14
Mac Os X MEDIUM 6.8
CVE-2009-2800

Buffer overflow in Alias Manager in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (applic…

Patch available
Fix from $1,600 2009-09-11
Iphone Os HIGH 7.8
CVE-2009-2815

The Telephony component in Apple iPhone OS before 3.1 does not properly handle SMS arrival notifications, which allows remote attackers to cause a de…

Fix: after 3.0.1
Fix from $1,950 2009-09-10
Iphone Os HIGH 7.2
CVE-2009-2795

Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allows local user…

Fix: 3.1 / 3.1.1+
Fix from $1,950 2009-09-10
Iphone Os MEDIUM 6.8
CVE-2009-2206

Multiple heap-based buffer overflows in the AudioCodecs library in the CoreAudio component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 …

Fix: after 3.0.1
Fix from $1,600 2009-09-10
Mac Os X MEDIUM 6.8
CVE-2009-2205

Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 10.5 before Update 5 allows attackers to execute arbitrary co…

Fix: after 2
Fix from $1,600 2009-09-09
Safari HIGH 9.3
CVE-2009-2195EPSS 13%

Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application cr…

Fix: after 4.0.2
Fix from $1,950 2009-08-12
Safari HIGH 7.1
CVE-2009-2200

WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-ass…

Fix: after 4.0.2
Fix from $1,950 2009-08-12
Safari MEDIUM 5.8
CVE-2009-2199

Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, an…

Fix: after 4.0.2
Fix from $1,600 2009-08-12
Safari MEDIUM 5.0
CVE-2009-2196

Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly…

Patch available
Fix from $1,600 2009-08-12
Mac Os X HIGH 10.0
CVE-2009-2193EPSS 9%

Buffer overflow in the kernel in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (sy…

Patch available
Fix from $1,950 2009-08-06
Mac Os X HIGH 9.3
CVE-2009-1726EPSS 8%

Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a…

Patch available
Fix from $1,950 2009-08-06
Mac Os X HIGH 9.3
CVE-2009-2188EPSS 8%

Buffer overflow in ImageIO in Apple Mac OS X 10.5 before 10.5.8, and Safari before 4.0.3, allows remote attackers to execute arbitrary code or cause …

Patch available
Fix from $1,950 2009-08-06
Mac Os X HIGH 7.8
CVE-2009-2190

launchd in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to cause a denial of service (individual service outage) by making many connecti…

Patch available
Fix from $1,950 2009-08-06