Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X HIGH 7.8
CVE-2007-0742

The WebFoundation framework in Apple Mac OS X 10.3.9 and earlier allows subdomain cookies to be accessed by the parent domain, which allows remote at…

Fix: after 10.3.9
Fix from $1,950 2007-04-24
Mac Os X HIGH 7.5
CVE-2007-0741EPSS 6%

Buffer overflow in natd in network_cmds in Apple Mac OS X 10.3.9 through 10.4.9, when Internet Sharing is enabled, allows remote attackers to execute…

Patch available
Fix from $1,950 2007-04-24
Mac Os X HIGH 7.2
CVE-2007-0744

SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privile…

Patch available
Fix from $1,950 2007-04-24
Mac Os X HIGH 7.2
CVE-2007-0747

load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local use…

Patch available
Fix from $1,950 2007-04-24
Safari HIGH 7.6
CVE-2007-2175EPSS 84%

Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2007-04-24
Mac Os X HIGH 7.2
CVE-2007-0725

Buffer overflow in the AirPortDriver module for AirPort in Apple Mac OS X 10.3.9 through 10.4.9, when running on hardware with the original AirPort w…

Mitigation only
Fix from $1,950 2007-04-24
Mac Os X HIGH 7.2
CVE-2007-0729

Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which all…

Patch available
Fix from $1,950 2007-04-24
Mac Os X HIGH 7.2
CVE-2007-0732

Unspecified vulnerability in the CoreServices daemon in CarbonCore in Apple Mac OS X 10.4 through 10.4.9 allows local users to gain privileges via un…

Mitigation only
Fix from $1,950 2007-04-24
Safari MEDIUM 5.0
CVE-2007-2163

Apple Safari allows remote attackers to cause a denial of service (browser crash) via JavaScript that matches a regular expression against a long str…

Mitigation only
Fix from $1,600 2007-04-22
Mac Os X MEDIUM 5.4
CVE-2007-0734

fsck, as used by the AirPort Disk feature of the AirPort Extreme Base Station with 802.11n before Firmware Update 7.1, and by Apple Mac OS X 10.3.9 t…

Patch available
Fix from $1,600 2007-04-10
Mac Os X HIGH 9.3
CVE-2007-0731

Stack-based buffer overflow in the Apple-specific Samba module (SMB File Server) in Apple Mac OS X 10.4 through 10.4.8 allows context-dependent attac…

Patch available
Fix from $1,950 2007-03-13
Imageio HIGH 9.3
CVE-2007-0733EPSS 7%

Unspecified vulnerability in ImageIO in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to cause a denial of serv…

Patch available
Fix from $1,950 2007-03-13
Mac Os X HIGH 8.5
CVE-2007-0723

Unspecified vulnerability in the authentication feature for DirectoryService (DS Plug-Ins) for Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows r…

Patch available
Fix from $1,950 2007-03-13
Mac Os X MEDIUM 6.9
CVE-2007-0724

The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local u…

Patch available
Fix from $1,600 2007-03-13
Mac Os X MEDIUM 6.8
CVE-2007-0721

Unspecified vulnerability in diskimages-helper in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbi…

Patch available
Fix from $1,600 2007-03-13
Mac Os X MEDIUM 6.8
CVE-2007-0722

Integer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted Apple…

Patch available
Fix from $1,600 2007-03-13
Server Manager MEDIUM 6.8
CVE-2007-0730

Server Manager (servermgrd) in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently validate authentication credentials, which allows …

Patch available
Fix from $1,600 2007-03-13
Mac Os X MEDIUM 5.0
CVE-2007-0726

The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote attackers to cause a denial of service by co…

Patch available
Fix from $1,600 2007-03-13
Mac Os X MEDIUM 6.8
CVE-2007-0719EPSS 6%

Stack-based buffer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via an i…

Patch available
Fix from $1,600 2007-03-13
Airport Extreme HIGH 7.5
CVE-2007-1338

The default configuration of the AirPort utility in Apple AirPort Extreme creates an IPv6 tunnel but does not enable the "Block incoming IPv6 connect…

No fix yet
Fix from $1,950 2007-03-08
Mac Os X HIGH 7.8
CVE-2007-1071EPSS 18%

Integer overflow in the gifGetBandProc function in ImageIO in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (segmentatio…

No fix yet
Fix from $1,950 2007-02-22
Safari HIGH 7.1
CVE-2007-0644

Format string vulnerability in Apple Safari 2.0.4 (419.3) allows remote user-assisted attackers to cause a denial of service (crash) via format strin…

Mitigation only
Fix from $1,950 2007-02-01
Safari HIGH 7.1
CVE-2007-0646EPSS 10%

Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a d…

No fix yet
Fix from $1,950 2007-02-01
Mac Os X HIGH 7.1
CVE-2007-0647

Format string vulnerability in Help Viewer 3.0.0 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifi…

No fix yet
Fix from $1,950 2007-02-01
Iphoto MEDIUM 6.8
CVE-2007-0645

Format string vulnerability in iPhoto 6.0.5 allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers i…

Mitigation only
Fix from $1,600 2007-02-01
Ichat HIGH 7.8
CVE-2007-0614EPSS 8%

The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a…

No fix yet
Fix from $1,950 2007-01-31
Ichat MEDIUM 5.0
CVE-2007-0613EPSS 7%

The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entri…

No fix yet
Fix from $1,600 2007-01-31
Mac Os X MEDIUM 6.2
CVE-2007-0467

crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on applica…

No fix yet
Fix from $1,600 2007-01-31
Installer HIGH 7.6
CVE-2007-0465EPSS 18%

Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format st…

No fix yet
Fix from $1,950 2007-01-31
Quicktime HIGH 7.1
CVE-2007-0588EPSS 6%

The InternalUnpackBits function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote a…

Mitigation only
Fix from $1,950 2007-01-30