Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X HIGH 10.0
CVE-2008-3616

Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial…

Patch available
Fix from $1,950 2008-09-16
Mac Os X HIGH 9.3
CVE-2008-2332

ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and appl…

Patch available
Fix from $1,950 2008-09-16
Mac Os X HIGH 9.3
CVE-2008-3608

ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and appl…

Patch available
Fix from $1,950 2008-09-16
Mac Os X HIGH 9.3
CVE-2008-3621EPSS 6%

VideoConference in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to cause a denial of service (memory corruption and applica…

Patch available
Fix from $1,950 2008-09-16
Mac Os X HIGH 9.0
CVE-2008-3618

The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their …

Patch available
Fix from $1,950 2008-09-16
Mac Os X HIGH 7.6
CVE-2008-3610

Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password a…

Patch available
Fix from $1,950 2008-09-16
Mac Os X HIGH 7.2
CVE-2008-3609

The kernel in Apple Mac OS X 10.5 through 10.5.4 does not properly flush cached credentials during recycling (aka purging) of a vnode, which might al…

Patch available
Fix from $1,950 2008-09-16
Mac Os X MEDIUM 6.3
CVE-2008-3611

Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, whic…

Patch available
Fix from $1,600 2008-09-16
Mac Os X MEDIUM 6.1
CVE-2008-3613

Finder in Apple Mac OS X 10.5.2 through 10.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) …

Patch available
Fix from $1,600 2008-09-16
Mac Os X MEDIUM 5.0
CVE-2008-2331

Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Info window after a lock operation that modifies Sha…

Patch available
Fix from $1,600 2008-09-16
Mac Os X MEDIUM 5.0
CVE-2008-3617

Remote Management and Screen Sharing in Apple Mac OS X 10.5 through 10.5.4, when used to set a password for a VNC viewer, displays additional input c…

Patch available
Fix from $1,600 2008-09-16
Safari MEDIUM 5.0
CVE-2008-3950EPSS 7%

Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod t…

Patch available
Fix from $1,600 2008-09-16
Mac Os X HIGH 9.3
CVE-2008-2305EPSS 5%

Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrar…

Patch available
Fix from $1,950 2008-09-16
Itunes HIGH 7.2
CVE-2008-3636

Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attacker…

Fix: after 7.6.1
Fix from $1,950 2008-09-11
Iphone Os CRITICAL 9.8
CVE-2008-3612

The Networking subsystem in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, uses predictable TCP initial sequence numbers, which al…

Fix: after 2.0.2
Fix from $2,300 2008-09-11
Iphone HIGH 9.3
CVE-2008-3632EPSS 6%

Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitr…

Patch available
Fix from $1,950 2008-09-11
Quicktime HIGH 9.3
CVE-2008-3635EPSS 6%

Stack-based buffer overflow in QuickTimeInternetExtras.qtx in an unspecified third-party Indeo v3.2 (aka IV32) codec for QuickTime, when used with Ap…

Fix: after 7.5
Fix from $1,950 2008-09-11
Ipod Touch HIGH 7.1
CVE-2008-3631

Application Sandbox in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, does not properly isolate third-party applications, which al…

Mitigation only
Fix from $1,950 2008-09-11
Bonjour MEDIUM 6.4
CVE-2008-3630

mDNSResponder in Apple Bonjour for Windows before 1.0.5, when an application uses the Bonjour API for unicast DNS, does not choose random values for …

Patch available
Fix from $1,600 2008-09-11
Bonjour MEDIUM 5.0
CVE-2008-2326EPSS 7%

mDNSResponder in the Bonjour Namespace Provider in Apple Bonjour for Windows before 1.0.5 allows attackers to cause a denial of service (NULL pointer…

Patch available
Fix from $1,600 2008-09-11
Safari MEDIUM 6.5
CVE-2008-3281

libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers…

Fix: 4.0+
Fix from $1,600 2008-08-27
Carboncore HIGH 9.3
CVE-2008-2320

Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through…

Patch available
Fix from $1,950 2008-08-04
Coregraphics HIGH 9.3
CVE-2008-2321EPSS 12%

Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of…

Patch available
Fix from $1,950 2008-08-04
Coregraphics HIGH 9.3
CVE-2008-2322EPSS 6%

Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11, 10.5.2, and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of…

Patch available
Fix from $1,950 2008-08-04
Quicklook HIGH 9.3
CVE-2008-2325

QuickLook in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and …

Patch available
Fix from $1,950 2008-08-04
Data Detectors Engine HIGH 7.1
CVE-2008-2323

Unspecified vulnerability in Data Detectors Engine in Apple Mac OS X 10.5.4 allows attackers to cause a denial of service (resource consumption) via …

Patch available
Fix from $1,950 2008-08-04
Mac Os X HIGH 8.1
CVE-2008-3438

Apple Mac OS X does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan …

Fix: after 10.5.4
Fix from $1,950 2008-08-01
Itunes HIGH 7.5
CVE-2008-3434

Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code v…

Fix: after 6.0.5
Fix from $1,950 2008-08-01
Safari MEDIUM 6.8
CVE-2008-3170

Apple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which could allow remote attackers to …

Mitigation only
Fix from $1,600 2008-07-14
Safari MEDIUM 5.0
CVE-2008-3171

Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to obtain potentially sensitive …

Mitigation only
Fix from $1,600 2008-07-14