Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X HIGH 7.2
CVE-2009-1235

XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, w…

Fix: after 10.5.6
Fix from $1,950 2009-04-02
Mac Os X HIGH 7.2
CVE-2009-1238

Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial…

Fix: after 10.5.6
Fix from $1,950 2009-04-02
Safari HIGH 9.3
CVE-2009-1060

Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via unknown vectors triggered by click…

No fix yet
Fix from $1,950 2009-03-24
Safari HIGH 9.3
CVE-2009-1042

Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via unknown vectors triggered by click…

Mitigation only
Fix from $1,950 2009-03-23
Itunes MEDIUM 5.0
CVE-2009-0016

Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) me…

Fix: after 8.0
Fix from $1,600 2009-03-14
Safari MEDIUM 5.0
CVE-2009-0744EPSS 7%

Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a feeds: U…

No fix yet
Fix from $1,600 2009-02-27
Cups MEDIUM 6.8
CVE-2009-0577

Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbit…

Patch available
Fix from $1,600 2009-02-20
Safari HIGH 10.0
CVE-2009-0137

Multiple unspecified vulnerabilities in Safari RSS in Apple Mac OS X 10.4.11 and 10.5.6, and Windows XP and Vista, allow remote attackers to execute …

Patch available
Fix from $1,950 2009-02-13
Mac Os X HIGH 10.0
CVE-2009-0138

servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify t…

Patch available
Fix from $1,950 2009-02-13
Mac Os X HIGH 9.3
CVE-2009-0139

Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a denial of service (system shutdown) or execute ar…

Patch available
Fix from $1,950 2009-02-13
Mac Os X HIGH 9.3
CVE-2009-0140

Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory ex…

Patch available
Fix from $1,950 2009-02-13
Mac Os X MEDIUM 5.5
CVE-2009-0141

XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local use…

Mitigation only
Fix from $1,600 2009-02-13
Mac Os X HIGH 10.0
CVE-2009-0012EPSS 5%

Heap-based buffer overflow in CoreText in Apple Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via a crafted Unicode string.

Patch available
Fix from $1,950 2009-02-13
Mac Os X HIGH 7.8
CVE-2009-0018

The Remote Apple Events server in Apple Mac OS X 10.4.11 and 10.5.6 does not properly initialize a buffer, which allows remote attackers to read port…

Mitigation only
Fix from $1,950 2009-02-13
Mac Os X HIGH 7.8
CVE-2009-0020

Unspecified vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termin…

Patch available
Fix from $1,950 2009-02-13
Mac Os X HIGH 7.5
CVE-2009-0019

Remote Apple Events in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) or obtain sen…

Mitigation only
Fix from $1,950 2009-02-13
Mac Os X HIGH 7.2
CVE-2009-0011

Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via unknown vectors related to an "insecure file opera…

Patch available
Fix from $1,950 2009-02-13
Mac Os X HIGH 7.2
CVE-2009-0017

csregprinter in the Printing component in Apple Mac OS X 10.4.11 and 10.5.6 does not properly handle error conditions, which allows local users to ex…

Patch available
Fix from $1,950 2009-02-13
Mac Os X MEDIUM 6.8
CVE-2009-0009

Unspecified vulnerability in the Pixlet codec in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application …

Mitigation only
Fix from $1,600 2009-02-13
Cups MEDIUM 6.9
CVE-2009-0032

CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrit…

Mitigation only
Fix from $1,600 2009-01-27
Quicktime Mpeg 2 Playback Component HIGH 7.6
CVE-2009-0008

Unspecified vulnerability in Apple QuickTime MPEG-2 Playback Component before 7.60.92.0 on Windows allows remote attackers to cause a denial of servi…

Mitigation only
Fix from $1,950 2009-01-22
Safari HIGH 7.1
CVE-2009-0123

Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vector…

No fix yet
Fix from $1,950 2009-01-15
Safari HIGH 9.3
CVE-2009-0070

Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (appli…

No fix yet
Fix from $1,950 2009-01-08
Safari MEDIUM 5.0
CVE-2008-5821

Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause a denial of service (memory c…

No fix yet
Fix from $1,600 2009-01-02
Mac Os X HIGH 10.0
CVE-2008-4220

Integer overflow in the inet_net_pton API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to execute arbitrary code o…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Mac Os X HIGH 10.0
CVE-2008-4221

The strptime API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to cause a denial of service (memory corruption and …

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Mac Os X Server HIGH 10.0
CVE-2008-4223EPSS 5%

Podcast Producer in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to bypass authentication and gain administrative access via unspecified…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Mac Os X HIGH 10.0
CVE-2008-4237

Managed Client in Apple Mac OS X before 10.5.6 sometimes misidentifies a system when installing per-host configuration settings, which allows context…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Mac Os X HIGH 9.3
CVE-2008-4217EPSS 5%

Integer signedness error in BOM in Apple Mac OS X before 10.5.6 allows remote attackers to execute arbitrary code via the headers in a crafted CPIO a…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Mac Os X HIGH 9.3
CVE-2008-4234

Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers …

Fix: after 10.5.5
Fix from $1,950 2008-12-17