Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X HIGH 7.2
CVE-2008-0055

Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permission…

Patch available
Fix from $1,950 2008-03-18
Mac Os X HIGH 7.1
CVE-2008-0999

Apple Mac OS X 10.5.2 allows user-assisted attackers to cause a denial of service (crash) via a crafted Universal Disc Format (UDF) disk image, which…

Patch available
Fix from $1,950 2008-03-18
Mac Os X MEDIUM 6.9
CVE-2008-0989

Format string vulnerability in mDNSResponderHelper in Apple Mac OS X 10.5.2 allows local users to execute arbitrary code via format string specifiers…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 6.9
CVE-2008-0998

Unspecified vulnerability in NetCfgTool in the System Configuration component in Apple Mac OS X 10.4.11 and 10.5.2 allows local users to bypass autho…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 6.8
CVE-2008-0052

CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 6.8
CVE-2008-0056

Stack-based buffer overflow in Foundation in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a "long pathname…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 6.8
CVE-2008-0060

Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML…

Patch available
Fix from $1,600 2008-03-18
Aperture MEDIUM 6.8
CVE-2008-0987

Stack-based buffer overflow in Image Raw in Apple Mac OS X 10.5.2, and Digital Camera RAW Compatibility before Update 2.0 for Aperture 2 and iPhoto 7…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 6.4
CVE-2008-0054

Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelecto…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 5.8
CVE-2008-0058

Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbi…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 5.8
CVE-2008-0059

Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file,…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 5.8
CVE-2008-0992

Array index error in pax in Apple Mac OS X 10.5.2 allows context-dependent attackers to execute arbitrary code via an archive with a crafted length v…

Patch available
Fix from $1,600 2008-03-18
Mac Os X HIGH 7.1
CVE-2008-0045

Unspecified vulnerability in AFP Server in Apple Mac OS X 10.4.11 allows remote attackers to bypass cross-realm authentication via unknown manipulati…

Patch available
Fix from $1,950 2008-03-18
Mac Os X MEDIUM 6.9
CVE-2008-0051

Integer overflow in CoreFoundation in Apple Mac OS X 10.4.11 might allow local users to execute arbitrary code via crafted time zone data.

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 6.8
CVE-2008-0048

Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via the a long file name…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 6.8
CVE-2008-0057

Multiple integer overflows in a "legacy serialization format" parser in AppKit in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 6.8
CVE-2008-0997

Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows user-assisted remote attackers to cause a denial of service (application termi…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 5.8
CVE-2008-0044

Multiple buffer overflows in AFP Client in Apple Mac OS X 10.4.11 and 10.5.2 allow remote attackers to cause a denial of service (application termina…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 5.0
CVE-2008-0046

The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the "Set access for specific services and applications" rad…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 5.0
CVE-2008-0050

CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via data in a 502 Bad Gateway error.

Patch available
Fix from $1,600 2008-03-18
Safari MEDIUM 6.8
CVE-2008-0894

Apple Safari might allow remote attackers to obtain potentially sensitive memory contents or cause a denial of service (crash) via a crafted (1) bitm…

Mitigation only
Fix from $1,600 2008-02-21
Iphoto HIGH 7.5
CVE-2008-0830

The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (crash) via a malformed dpap: U…

No fix yet
Fix from $1,950 2008-02-19
Mobile Safari HIGH 7.1
CVE-2008-0729EPSS 8%

Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain J…

No fix yet
Fix from $1,950 2008-02-12
Mac Os X HIGH 10.0
CVE-2008-0040EPSS 7%

Unspecified vulnerability in NFS in Apple Mac OS X 10.5 through 10.5.1 allows remote attackers to cause a denial of service (system shutdown) or exec…

Patch available
Fix from $1,950 2008-02-12
Mail MEDIUM 6.8
CVE-2008-0039

Unspecified vulnerability in Mail in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary commands via a crafted file:// URL.

Patch available
Fix from $1,600 2008-02-12
Mac Os X MEDIUM 6.8
CVE-2008-0042

Argument injection vulnerability in Terminal.app in Terminal in Apple Mac OS X 10.4.11 and 10.5 through 10.5.1 allows remote attackers to execute arb…

Patch available
Fix from $1,600 2008-02-12
Mac Os X MEDIUM 5.0
CVE-2008-0041

Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is unblocked," which allows remote attackers to determ…

Patch available
Fix from $1,600 2008-02-12
Iphoto HIGH 9.3
CVE-2008-0043

Format string vulnerability in Apple iPhoto before 7.1.2 allows remote attackers to execute arbitrary code via photocast subscriptions.

Fix: after 7.1
Fix from $1,950 2008-02-08
Safari MEDIUM 6.8
CVE-2008-0035EPSS 5%

Unspecified vulnerability in Foundation, as used in Apple iPhone 1.0 through 1.1.2, iPod touch 1.1 through 1.1.2, and Mac OS X 10.5 through 10.5.1, a…

Mitigation only
Fix from $1,600 2008-01-16
Mac Os X HIGH 9.4
CVE-2007-5856

Quick Look Apple Mac OS X 10.5.1, when previewing an HTML file, does not prevent plug-ins from making network requests, which might allow remote atta…

Mitigation only
Fix from $1,950 2007-12-19