Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Safari HIGH 10.0
CVE-2008-2303EPSS 13%

Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a …

Mitigation only
Fix from $1,950 2008-07-14
Safari HIGH 9.3
CVE-2008-2317EPSS 8%

WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2008-07-14
Core Image Fun House MEDIUM 6.8
CVE-2008-2304EPSS 6%

Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows user-assisted attackers to execu…

Fix: after 2.0
Fix from $1,600 2008-07-14
Xcode MEDIUM 5.0
CVE-2008-2318

The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remo…

Fix: after 3.0
Fix from $1,600 2008-07-14
Mac Os X HIGH 7.6
CVE-2008-2311

Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attac…

Patch available
Fix from $1,950 2008-07-01
Mac Os X MEDIUM 6.8
CVE-2008-2309

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a…

Patch available
Fix from $1,600 2008-07-01
Mac Os X MEDIUM 6.8
CVE-2008-2310

Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denia…

Fix: after 10.5.3
Fix from $1,600 2008-07-01
Safari HIGH 9.3
CVE-2008-2306

Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows re…

Fix: after 3.1.1
Fix from $1,950 2008-06-23
Safari HIGH 9.3
CVE-2008-2307EPSS 7%

Unspecified vulnerability in WebKit in Apple Safari before 3.1.2, as distributed in Mac OS X before 10.5.4, and standalone for Windows and Mac OS X 1…

Fix: after 3.1.1
Fix from $1,950 2008-06-23
Mac Os X HIGH 7.2
CVE-2008-2830

Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of sc…

No fix yet
Fix from $1,950 2008-06-23
Safari HIGH 9.3
CVE-2008-2540EPSS 8%

Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, w…

Fix: 3.1.2+
Fix from $1,950 2008-06-03
Mac Os X HIGH 10.0
CVE-2008-1030

Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent atta…

Mitigation only
Fix from $1,950 2008-06-02
Mac Os X HIGH 9.3
CVE-2008-1028

Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial o…

Mitigation only
Fix from $1,950 2008-06-02
Mac Os X HIGH 9.3
CVE-2008-1031EPSS 6%

CoreGraphics in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a…

Mitigation only
Fix from $1,950 2008-06-02
Mac Os X HIGH 9.3
CVE-2008-1034EPSS 8%

Integer underflow in Help Viewer in Apple Mac OS X before 10.5 allows remote attackers to execute arbitrary code or cause a denial of service (applic…

Fix: after 10.4
Fix from $1,950 2008-06-02
Mac Os X HIGH 9.3
CVE-2008-1574EPSS 7%

Integer overflow in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (applicati…

Patch available
Fix from $1,950 2008-06-02
Mac Os X HIGH 9.3
CVE-2008-1575EPSS 6%

Unspecified vulnerability in the Apple Type Services (ATS) server in Apple Mac OS X 10.5 before 10.5.3 allows user-assisted remote attackers to execu…

Patch available
Fix from $1,950 2008-06-02
Mac Os X HIGH 9.3
CVE-2008-1577EPSS 6%

Unspecified vulnerability in the Pixlet codec in Apple Pixlet Video in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code…

Patch available
Fix from $1,950 2008-06-02
Mac Os X HIGH 7.1
CVE-2008-1573

The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to obtain sensitive information (memory cont…

Fix: after 10.5.2
Fix from $1,950 2008-06-02
Mac Os X MEDIUM 6.8
CVE-2008-1032

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via a…

Patch available
Fix from $1,600 2008-06-02
Mac Os X MEDIUM 6.8
CVE-2008-1576

Mail in Apple Mac OS X before 10.5, when an IPv6 SMTP server is used, does not properly initialize memory, which might allow remote attackers to exec…

Patch available
Fix from $1,600 2008-06-02
Mac Os X MEDIUM 5.0
CVE-2008-1571

Directory traversal vulnerability in the embedded web server in Image Capture in Apple Mac OS X before 10.5 allows remote attackers to read arbitrary…

Patch available
Fix from $1,600 2008-06-02
Mac Os X MEDIUM 5.0
CVE-2008-1579

Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message pr…

Patch available
Fix from $1,600 2008-06-02
Safari MEDIUM 5.0
CVE-2008-1999

Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userinfo subcomponent of the author…

Mitigation only
Fix from $1,600 2008-04-28
Safari MEDIUM 6.8
CVE-2008-1024

Apple Safari before 3.1.1, when running on Windows XP or Vista, allows remote attackers to cause a denial of service (crash) and possibly execute arb…

Mitigation only
Fix from $1,600 2008-04-17
Safari MEDIUM 6.8
CVE-2008-1026

Integer overflow in the PCRE regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in Apple WebKit, as used in Safari before 3.1.1, allo…

Patch available
Fix from $1,600 2008-04-17
Cups MEDIUM 6.8
CVE-2008-1374

Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute …

Fix: after 1.3.11
Fix from $1,600 2008-04-04
Safari MEDIUM 6.8
CVE-2008-1010

Buffer overflow in WebKit, as used in Apple Safari before 3.1, allows remote attackers to execute arbitrary code via crafted regular expressions in J…

Patch available
Fix from $1,600 2008-03-19
Cups HIGH 10.0
CVE-2008-0053EPSS 8%

Multiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3.6 might allow remote attackers to execute arbitrary code via a craft…

Fix: after 1.3.5
Fix from $1,950 2008-03-18
Mac Os X HIGH 8.5
CVE-2008-1000

Directory traversal vulnerability in ContentServer.py in the Wiki Server in Apple Mac OS X 10.5.2 (aka Leopard) allows remote authenticated users to …

Patch available
Fix from $1,950 2008-03-18