Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X HIGH 7.2
CVE-2007-4269

Integer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleT…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 7.2
CVE-2007-4685

The kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to gain privileges by executing setuid or setgid programs in which the stdio, st…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 7.2
CVE-2007-4686

Integer signedness error in the ttioctl function in bsd/kern/tty.c in the xnu kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to cau…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 7.2
CVE-2007-4693

The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen …

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 7.1
CVE-2007-4678

AppleRAID in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows attackers to cause a denial of service (crash) via a crafted striped disk image, w…

Patch available
Fix from $1,950 2007-11-15
Mac Os X MEDIUM 6.9
CVE-2007-4681

Buffer overflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows local users to cause a denial of service (application cras…

Mitigation only
Fix from $1,600 2007-11-15
Mac Os X MEDIUM 6.9
CVE-2007-4684

Integer overflow in the kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a large num_sels argument to t…

Mitigation only
Fix from $1,600 2007-11-15
Mac Os X MEDIUM 6.8
CVE-2007-4680

CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted S…

Patch available
Fix from $1,600 2007-11-15
Mac Os X MEDIUM 6.8
CVE-2007-4682

CoreText in Apple Mac OS X 10.4 through 10.4.10 allows attackers to cause a denial of service (application crash) and possibly execute arbitrary code…

Fix: after 10.4.10
Fix from $1,600 2007-11-15
Mac Os X MEDIUM 6.8
CVE-2007-4697

Unspecified vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application termina…

Patch available
Fix from $1,600 2007-11-15
Mac Os X MEDIUM 5.0
CVE-2007-4688

The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain all addresses for a host, including link-local addr…

Patch available
Fix from $1,600 2007-11-15
Mac Os X HIGH 9.3
CVE-2007-3751EPSS 26%

Unspecified vulnerability in QuickTime for Java in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via untrusted Java ap…

Patch available
Fix from $1,950 2007-11-07
Mac Os X HIGH 9.3
CVE-2007-4675EPSS 33%

Heap-based buffer overflow in the QuickTime VR extension 7.2.0.240 in QuickTime.qts in Apple QuickTime before 7.3 allows remote attackers to execute …

Patch available
Fix from $1,950 2007-11-07
Mac Os X HIGH 9.3
CVE-2007-4676EPSS 47%

Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Po…

Mitigation only
Fix from $1,950 2007-11-07
Mac Os X HIGH 9.3
CVE-2007-4677EPSS 47%

Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via an invalid color table size when parsi…

Mitigation only
Fix from $1,950 2007-11-07
Safari HIGH 9.3
CVE-2007-5450

Unspecified vulnerability in Safari on the Apple iPod touch (aka iTouch) and iPhone 1.1.1 allows user-assisted remote attackers to cause a denial of …

No fix yet
Fix from $1,950 2007-10-14
Safari MEDIUM 6.8
CVE-2007-3759

Safari in Apple iPhone 1.1.1, when requested to disable Javascript, does not disable it until Safari is restarted, which might leave Safari open to a…

Patch available
Fix from $1,600 2007-09-27
Safari MEDIUM 6.8
CVE-2007-4671

Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows…

Fix: after 3.0.3
Fix from $1,600 2007-09-27
Iphone HIGH 7.5
CVE-2007-3753

Apple iPhone 1.1.1, with Bluetooth enabled, allows physically proximate attackers to cause a denial of service (application termination) and execute …

Patch available
Fix from $1,950 2007-09-27
Safari MEDIUM 5.0
CVE-2007-4812

Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to cause a denial of service (cr…

Mitigation only
Fix from $1,600 2007-09-11
Itunes HIGH 9.3
CVE-2007-3752EPSS 6%

Heap-based buffer overflow in Apple iTunes before 7.4 allows remote attackers to cause a denial of service (application crash) or execute arbitrary c…

Fix: after 7.3.2
Fix from $1,950 2007-09-06
Safari MEDIUM 6.8
CVE-2007-4431

Cross-domain vulnerability in Apple Safari for Windows 3.0.3 and earlier allows remote attackers to bypass the Same Origin Policy, with access from l…

Fix: after 3.0.3
Fix from $1,600 2007-08-20
Safari MEDIUM 6.8
CVE-2007-2408

WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked "Enable Java" setting, which allows remote attackers to ex…

Patch available
Fix from $1,600 2007-08-03
Safari MEDIUM 6.8
CVE-2007-3743

Stack-based buffer overflow in bookmark handling in Apple Safari 3 Beta before Update 3.0.3 on Windows allows user-assisted remote attackers to cause…

Fix: after 3.0.2
Fix from $1,600 2007-08-03
Cfnetwork MEDIUM 6.8
CVE-2007-2403

CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 does not properly validate ftp: URIs, which allows remote attackers to trigger the transmission of arb…

Patch available
Fix from $1,600 2007-08-03
Pdfkit MEDIUM 6.8
CVE-2007-2405

Integer underflow in Preview in PDFKit on Apple Mac OS X 10.4.10 allows remote attackers to execute arbitrary code via a crafted PDF file.

Patch available
Fix from $1,600 2007-08-03
Quartz Composer MEDIUM 6.8
CVE-2007-2406

Quartz Composer on Apple Mac OS X 10.4.10 does not initialize a certain object pointer, which might allow user-assisted remote attackers to execute a…

Patch available
Fix from $1,600 2007-08-03
Core Audio Technologies MEDIUM 6.8
CVE-2007-3745

The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 contains an unsafe interface that is exposed by JDirect, which allows remote att…

Patch available
Fix from $1,600 2007-08-03
Ichat MEDIUM 6.8
CVE-2007-3746

The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not properly check the bounds of heap read and write operations, which allo…

Patch available
Fix from $1,600 2007-08-03
Ichat MEDIUM 6.8
CVE-2007-3747

The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not restrict object instantiation and manipulation to valid heap addresses,…

Patch available
Fix from $1,600 2007-08-03