Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X HIGH 9.3
CVE-2007-4708EPSS 5%

Format string vulnerability in Address Book in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via the URL handler.

Mitigation only
Fix from $1,950 2007-12-19
Mac Os X HIGH 9.3
CVE-2007-4710

Unspecified vulnerability in ColorSync in Apple Mac OS X 10.4.11 allows remote attackers to cause a denial of service (application termination) or ex…

Mitigation only
Fix from $1,950 2007-12-19
Mac Os X HIGH 9.3
CVE-2007-5853

Unspecified vulnerability in IO Storage Family in Apple Mac OS X 10.4.11 allows user-assisted attackers to cause a denial of service (system shutdown…

Mitigation only
Fix from $1,950 2007-12-19
Safari HIGH 9.3
CVE-2007-5859EPSS 6%

Unspecified vulnerability in Safari RSS in Apple Mac OS X 10.4.11 allows remote attackers to cause a denial of service (application termination) or e…

Mitigation only
Fix from $1,950 2007-12-19
Mac Os X HIGH 9.3
CVE-2007-5863EPSS 23%

Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between the clie…

Mitigation only
Fix from $1,950 2007-12-19
Mac Os X HIGH 8.8
CVE-2007-4709

Directory traversal vulnerability in CFNetwork in Apple Mac OS X 10.5.1 allows remote attackers to overwrite arbitrary files via a crafted HTTP respo…

Mitigation only
Fix from $1,950 2007-12-19
Mac Os X HIGH 8.8
CVE-2007-5850

Heap-based buffer overflow in Desktop Services in Apple Mac OS X 10.4.11 allows user-assisted attackers to execute arbitrary code via a directory wit…

Mitigation only
Fix from $1,950 2007-12-19
Mac Os X HIGH 7.2
CVE-2007-5848

Buffer overflow in CUPS in Apple Mac OS X 10.4.11 allows local admin users to execute arbitrary code via a crafted URI to the CUPS service.

Mitigation only
Fix from $1,950 2007-12-19
Mac Os X HIGH 7.2
CVE-2007-5860

Unspecified vulnerability in Spin Tracer in Apple Mac OS X 10.5.1 allows local users to execute arbitrary code via unspecified output files, involvin…

Mitigation only
Fix from $1,950 2007-12-19
Mac Os X MEDIUM 6.8
CVE-2007-5861

Unspecified vulnerability in Spotlight in Apple Mac OS X 10.4.11 allows user-assisted attackers to cause a denial of service (application termination…

Mitigation only
Fix from $1,600 2007-12-19
Mac Os X MEDIUM 6.6
CVE-2007-3876

Stack-based buffer overflow in SMB in Apple Mac OS X 10.4.11 allows local users to execute arbitrary code via (1) a long workgroup (-W) option to mou…

No fix yet
Fix from $1,600 2007-12-19
Mac Os X MEDIUM 6.6
CVE-2007-5847

Race condition in the CFURLWriteDataAndPropertiesToResource API in Core Foundation in Apple Mac OS X 10.4.11 creates files with insecure permissions,…

Mitigation only
Fix from $1,600 2007-12-19
Mac Os X MEDIUM 6.4
CVE-2007-5855

Mail in Apple Mac OS X 10.4.11 and 10.5.1, when an SMTP account has been set up using Account Assistant, can use plaintext authentication even when M…

Mitigation only
Fix from $1,600 2007-12-19
Mac Os X MEDIUM 6.4
CVE-2007-5857

Quick Look in Apple Mac OS X 10.5.1 does not prevent a movie from accessing URLs when the movie file is previewed or if an icon is created, which mig…

Mitigation only
Fix from $1,600 2007-12-19
Mac Os X HIGH 9.4
CVE-2007-5862

Java in Mac OS X 10.4 through 10.4.11 allows remote attackers to bypass Keychain access controls and add or delete arbitrary Keychain items via a cra…

Patch available
Fix from $1,950 2007-12-18
Mac Os X HIGH 7.8
CVE-2007-6276EPSS 9%

The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows remote attackers to cause a …

No fix yet
Fix from $1,950 2007-12-07
Mac Os X HIGH 9.3
CVE-2007-6165EPSS 45%

Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an a…

No fix yet
Fix from $1,950 2007-11-29
Safari HIGH 9.3
CVE-2007-6166EPSS 42%

Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Tim…

Fix: after 7.3
Fix from $1,950 2007-11-29
Mac Os X HIGH 10.0
CVE-2007-4703

The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when "Block incoming connec…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 10.0
CVE-2007-4704

The Application Firewall in Apple Mac OS X 10.5 does not apply changed settings to processes that are started by launchd until the processes are rest…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 9.3
CVE-2007-4702

The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder f…

Patch available
Fix from $1,950 2007-11-15
Safari HIGH 7.5
CVE-2007-4699

The default configuration of Safari in Apple Mac OS X 10.4 through 10.4.10 adds a private key to the keychain with permissions that allow other appli…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 7.5
CVE-2007-4700

Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to use Safari as an indirect proxy and send attack…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 10.0
CVE-2007-4689EPSS 7%

Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (sy…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 10.0
CVE-2007-4691

The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that allow attackers to bypass intended restrictions f…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 9.3
CVE-2007-4687

The remote_cmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the tftpboot private directory to the root directory, …

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 9.0
CVE-2007-4690

Double free vulnerability in the NFS component in Apple Mac OS X 10.4 through 10.4.10 allows remote authenticated users to execute arbitrary code via…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 7.8
CVE-2007-3749

The kernel in Apple Mac OS X 10.4 through 10.4.10 does not reset the current Mach Thread Port or Thread Exception Port when executing a setuid progra…

Fix: after 10.4.10
Fix from $1,950 2007-11-15
Mac Os X HIGH 7.8
CVE-2007-4268

Integer signedness error in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafte…

Fix: after 10.4.10
Fix from $1,950 2007-11-15
Mac Os X HIGH 7.2
CVE-2007-4267

Stack-based buffer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a cra…

Mitigation only
Fix from $1,950 2007-11-15