Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Safari MEDIUM 5.0
CVE-2009-1696

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 uses predictable random numbers in Jav…

Fix: after 4.0_beta
Fix from $1,600 2009-06-10
Safari MEDIUM 5.0
CVE-2009-1706

The Private Browsing feature in Apple Safari before 4.0 on Windows does not remove cookies from the alternate cookie store in unspecified circumstanc…

Fix: after 3.2.3
Fix from $1,600 2009-06-10
Safari HIGH 9.3
CVE-2009-1686EPSS 8%

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle constant (aka…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1687EPSS 8%

The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 do…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1690EPSS 7%

Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, …

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari MEDIUM 5.8
CVE-2009-1693

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to read images…

Fix: after 4.0_beta
Fix from $1,600 2009-06-10
Safari MEDIUM 5.8
CVE-2009-1694

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, wh…

Fix: after 4.0_beta
Fix from $1,600 2009-06-10
Cups MEDIUM 5.0
CVE-2009-1196

The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon ou…

Patch available
Fix from $1,600 2009-06-09
Cups MEDIUM 6.8
CVE-2009-0791EPSS 6%

Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphic…

Patch available
Fix from $1,600 2009-06-09
Mac Os X MEDIUM 6.8
CVE-2009-1717

Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (mem…

Patch available
Fix from $1,600 2009-06-05
Itunes HIGH 9.3
CVE-2009-0950EPSS 29%

Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a denial of service (application cr…

Fix: after 8.1.1
Fix from $1,950 2009-06-02
Safari HIGH 9.3
CVE-2009-0945EPSS 9%

Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPho…

Fix: after 3.2.2
Fix from $1,950 2009-05-13
Mac Os X HIGH 9.3
CVE-2009-0010EPSS 8%

Integer underflow in QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, and Apple QuickTime before 7.6.2, allows remote attackers to…

Patch available
Fix from $1,950 2009-05-13
Mac Os X HIGH 7.5
CVE-2009-0152

iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communication in certain circumstances that are inconsistent …

Fix: 10.5.7+
Fix from $1,950 2009-05-13
Mac Os X HIGH 7.2
CVE-2008-1517

Array index error in the xnu (Mach) kernel in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (s…

Patch available
Fix from $1,950 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0145EPSS 5%

CoreGraphics in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows rem…

Patch available
Fix from $1,600 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0154EPSS 6%

Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary…

Patch available
Fix from $1,600 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0155EPSS 6%

Integer underflow in CoreGraphics in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 a…

Patch available
Fix from $1,600 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0157

Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web servers to execute arbitrary code or cause a denial of…

Patch available
Fix from $1,600 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0158

Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a d…

Patch available
Fix from $1,600 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0160

QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (ap…

Patch available
Fix from $1,600 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0942

Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) are located in a registered he…

Patch available
Fix from $1,600 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0943

Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows …

Patch available
Fix from $1,600 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0944

The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office fil…

Patch available
Fix from $1,600 2009-05-13
Mac Os X MEDIUM 6.4
CVE-2009-0161

The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate…

Patch available
Fix from $1,600 2009-05-13
Safari HIGH 9.3
CVE-2009-1600

Apple Safari executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF…

Mitigation only
Fix from $1,950 2009-05-11
Cups MEDIUM 6.4
CVE-2009-0164

The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to co…

Fix: after 1.3.9
Fix from $1,600 2009-04-24
Cups MEDIUM 6.8
CVE-2009-0163

Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) an…

Fix: after 1.3.9
Fix from $1,600 2009-04-23
Cups MEDIUM 6.8
CVE-2009-0195EPSS 5%

Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code vi…

Fix: after 3.02
Fix from $1,600 2009-04-23
Mac Os X HIGH 10.0
CVE-2009-1236EPSS 8%

Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attacker…

Fix: after 10.5.6
Fix from $1,950 2009-04-02