Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X HIGH 7.2
CVE-2008-4218

Multiple integer overflows in the kernel in Apple Mac OS X before 10.5.6 on Intel platforms allow local users to gain privileges via a crafted call t…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Mac Os X HIGH 7.1
CVE-2008-4222

natd in network_cmds in Apple Mac OS X before 10.5.6, when Internet Sharing is enabled, allows remote attackers to cause a denial of service (infinit…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Mac Os X HIGH 7.1
CVE-2008-4224

UDF in Apple Mac OS X before 10.5.6 allows user-assisted attackers to cause a denial of service (system crash) via a malformed UDF volume in a crafte…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Mac Os X HIGH 7.1
CVE-2008-4236

Apple Type Services (ATS) in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to cause a denial of service (infinite loop) via a crafted emb…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Itunes HIGH 9.3
CVE-2008-5406EPSS 10%

Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application cra…

No fix yet
Fix from $1,950 2008-12-10
Cups MEDIUM 6.9
CVE-2008-5377

pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulner…

No fix yet
Fix from $1,600 2008-12-08
Iphone Configuration Web Utility HIGH 7.8
CVE-2008-5315

Directory traversal vulnerability in the web interface in Apple iPhone Configuration Web Utility 1.0 on Windows allows remote attackers to read arbit…

Mitigation only
Fix from $1,950 2008-12-03
Cups HIGH 7.5
CVE-2008-5286

Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image wit…

Patch available
Fix from $1,950 2008-12-01
Safari HIGH 9.3
CVE-2008-4231EPSS 6%

Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not properly handle HTML TABLE elements, which allows rem…

Mitigation only
Fix from $1,950 2008-11-25
Iphone Os HIGH 7.5
CVE-2008-4227

Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 changes the encryption level of PPTP VPN connections to a lower level th…

Mitigation only
Fix from $1,950 2008-11-25
Iphone Os HIGH 7.1
CVE-2008-1586

ImageIO in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allow remote attackers to cause a denial of service (memory c…

Mitigation only
Fix from $1,950 2008-11-25
Safari MEDIUM 5.0
CVE-2008-4232

Safari in Apple iPhone OS 2.0 through 2.1 and iPhone OS for iPod touch 2.1 through 2.1 does not restrict an IFRAME's content display to the boundarie…

Mitigation only
Fix from $1,600 2008-11-25
Cups HIGH 10.0
CVE-2008-5184

The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easie…

Fix: after 1.3.7
Fix from $1,950 2008-11-21
Safari HIGH 9.3
CVE-2008-3623EPSS 8%

Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1…

Fix: after 3.1.2
Fix from $1,950 2008-11-17
Cups HIGH 7.5
CVE-2008-3639

Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI …

Fix: after 1.3.8
Fix from $1,950 2008-10-14
Cups MEDIUM 6.8
CVE-2008-3640

Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScr…

Fix: after 1.3.8
Fix from $1,600 2008-10-14
Mac Os X HIGH 10.0
CVE-2008-4211EPSS 7%

Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod to…

Patch available
Fix from $1,950 2008-10-10
Mac Os X HIGH 10.0
CVE-2008-4212

Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite what is state…

Patch available
Fix from $1,950 2008-10-10
Mac Os X HIGH 9.3
CVE-2008-3647

Buffer overflow in PSNormalizer in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and exe…

Patch available
Fix from $1,950 2008-10-10
Mac Os X Server HIGH 7.5
CVE-2008-4215

Weblog in Mac OS X Server 10.4.11 does not properly check an error condition when a weblog posting access control list is specified for a user that h…

Patch available
Fix from $1,950 2008-10-10
Mac Os X MEDIUM 6.8
CVE-2008-3646

The Postfix configuration file in Mac OS X 10.5.5 causes Postfix to be network-accessible when mail is sent from a local command-line tool, which all…

Patch available
Fix from $1,600 2008-10-10
Mac Os X HIGH 9.3
CVE-2008-3642EPSS 6%

Buffer overflow in ColorSync in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and possib…

Patch available
Fix from $1,950 2008-10-10
Mac Os X HIGH 7.8
CVE-2008-3643

Unspecified vulnerability in Finder in Mac OS X 10.5.5 allows user-assisted attackers to cause a denial of service (continuous termination and restar…

Patch available
Fix from $1,950 2008-10-10
Mac Os X HIGH 7.2
CVE-2008-3645

Heap-based buffer overflow in the local IPC component in the EAPOLController plugin for configd (Networking component) in Mac OS X 10.4.11 and 10.5.5…

Patch available
Fix from $1,950 2008-10-10
Cups HIGH 10.0
CVE-2008-3641EPSS 24%

The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and …

Fix: after 1.3.8
Fix from $1,950 2008-10-10
Mail MEDIUM 5.0
CVE-2008-4491

Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME email in plaintext on the email s…

Mitigation only
Fix from $1,600 2008-10-08
Mac Os X MEDIUM 5.0
CVE-2008-4368

The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE…

Mitigation only
Fix from $1,600 2008-10-01
Mac Os X HIGH 9.3
CVE-2008-3638

Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary pro…

Mitigation only
Fix from $1,950 2008-09-26
Mac Os X HIGH 8.8
CVE-2008-3637EPSS 6%

The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized variable, whic…

Mitigation only
Fix from $1,950 2008-09-26
Itunes HIGH 9.3
CVE-2008-4116EPSS 12%

Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbi…

No fix yet
Fix from $1,950 2008-09-18