Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Software Update MEDIUM 5.0
CVE-2007-0463EPSS 18%

Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash…

No fix yet
Fix from $1,600 2007-01-29
Quicktime HIGH 10.0
CVE-2007-0462EPSS 7%

The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8 and earlier, allows remote at…

Mitigation only
Fix from $1,950 2007-01-26
Mac Os X MEDIUM 6.9
CVE-2007-0023

The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows loc…

No fix yet
Fix from $1,600 2007-01-24
Ichat HIGH 7.5
CVE-2007-0021EPSS 23%

Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash…

No fix yet
Fix from $1,950 2007-01-23
Mac Os X HIGH 7.2
CVE-2007-0022

Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a modified PATH that points to …

No fix yet
Fix from $1,950 2007-01-23
Minimal Slp Service Agent HIGH 7.2
CVE-2007-0355EPSS 7%

Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly …

No fix yet
Fix from $1,950 2007-01-19
Safari HIGH 7.5
CVE-2007-0342

WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element wi…

No fix yet
Fix from $1,950 2007-01-18
Mac Os X MEDIUM 6.8
CVE-2007-0345

The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/R…

No fix yet
Fix from $1,600 2007-01-18
Mac Os X HIGH 7.8
CVE-2007-0318

The do_hfs_truncate function in Mac OS X 10.4.8 allows context-dependent attackers to cause a denial of service (kernel panic) via a crafted HFS+ fil…

Mitigation only
Fix from $1,950 2007-01-18
Mac Os X HIGH 7.1
CVE-2007-0299

Integer overflow in the byte_swap_sbin function in bsd/ufs/ufs/ufs_byte_order.c in Mac OS X 10.4.8 allows user-assisted remote attackers to cause a d…

Mitigation only
Fix from $1,950 2007-01-17
Mac Os X HIGH 10.0
CVE-2007-0236EPSS 21%

Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to cause a denial…

No fix yet
Fix from $1,950 2007-01-16
Mac Os X MEDIUM 6.8
CVE-2007-0197EPSS 8%

Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a l…

No fix yet
Fix from $1,600 2007-01-11
Mac Os X HIGH 10.0
CVE-2007-0117EPSS 5%

DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials (BOM) files, which allows at…

No fix yet
Fix from $1,950 2007-01-09
Preview MEDIUM 6.8
CVE-2007-0102

The Adobe PDF specification 1.3, as implemented by Apple Mac OS X Preview, allows remote attackers to have an unknown impact, possibly including deni…

Patch available
Fix from $1,600 2007-01-09
Iphoto MEDIUM 6.8
CVE-2007-0051EPSS 9%

Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted attackers to execute arbitrary …

No fix yet
Fix from $1,600 2007-01-04
Mac Os X HIGH 10.0
CVE-2006-6900

Unspecified vulnerability in the Bluetooth stack in Apple Mac OS 10.4 has unknown impact and attack vectors, related to an "implementation bug."

No fix yet
Fix from $1,950 2006-12-31
Mac Os X HIGH 7.2
CVE-2006-6906

Unspecified vulnerability in the Bluetooth stack on Mac OS 10.4.7 and earlier has unknown impact and local attack vectors, related to "Mach Exception…

Fix: after 10.4.7
Fix from $1,950 2006-12-31
Mac Os X HIGH 9.0
CVE-2006-6652EPSS 20%

Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X…

Patch available
Fix from $1,950 2006-12-20
Bomarchivehelper MEDIUM 5.0
CVE-2006-6353

Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application c…

No fix yet
Fix from $1,600 2006-12-07
Mac Os X MEDIUM 5.7
CVE-2006-6292

Apple Airport Extreme firmware 0.1.27 in Mac OS X 10.4.8 on Mac mini, MacBook, and MacBook Pro with Core Duo hardware allows remote attackers to caus…

Patch available
Fix from $1,600 2006-12-05
Safari MEDIUM 5.0
CVE-2006-6238

The AutoFill feature in Apple Safari 2.0.4 does not properly verify that all automatically populated form fields are visible to the user, which allow…

No fix yet
Fix from $1,600 2006-12-03
Mac Os X HIGH 10.0
CVE-2006-4404

The Installer application in Apple Mac OS X 10.4.8 and earlier, when used by a user with Admin credentials, does not authenticate the user before ins…

Fix: after 10.4.8
Fix from $1,950 2006-11-30
Mac Os X HIGH 7.5
CVE-2006-4406EPSS 7%

Buffer overflow in PPP on Apple Mac OS X 10.4.x up to 10.4.8 and 10.3.x up to 10.3.9, when PPPoE is enabled, allows remote attackers to execute arbit…

Mitigation only
Fix from $1,950 2006-11-30
Mac Os X HIGH 7.5
CVE-2006-4410

The Security Framework in Apple Mac OS X 10.3.9, and 10.4.x before 10.4.7, does not properly search certificate revocation lists (CRL), which allows …

Mitigation only
Fix from $1,950 2006-11-30
Mac Os X HIGH 7.2
CVE-2006-4398

Multiple buffer overflows in the Apple Type Services (ATS) server in Mac OS X 10.4 through 10.4.8 allow local users to execute arbitrary code via cra…

Mitigation only
Fix from $1,950 2006-11-30
Mac Os X HIGH 7.2
CVE-2006-4411

The VPN service in Apple Mac OS X 10.3.x through 10.3.9 and 10.4.x through 10.4.8 does not properly clean the environment when executing commands, wh…

Patch available
Fix from $1,950 2006-11-30
Mac Os X HIGH 7.2
CVE-2006-6173

Buffer overflow in the shared_region_make_private_np function in vm/vm_unix.c in Mac OS X 10.4.6 and earlier allows local users to execute arbitrary …

Fix: after 10.4.6
Fix from $1,950 2006-11-30
Mac Os X MEDIUM 6.8
CVE-2006-4412EPSS 5%

WebKit in Apple Mac OS X 10.3.x through 10.3.9 and 10.4 through 10.4.8 allows remote attackers to execute arbitrary code via a crafted HTML file, whi…

Patch available
Fix from $1,600 2006-11-30
Mac Os X MEDIUM 5.1
CVE-2006-4400

Stack-based buffer overflow in the Apple Type Services (ATS) server in Mac OS 10.4.8 and earlier allow user-assisted attackers to execute arbitrary c…

Fix: after 10.4.8
Fix from $1,600 2006-11-30
Mac Os X MEDIUM 5.1
CVE-2006-4401

Unspecified vulnerability in CFNetwork in Mac OS 10.4.8 and earlier allows user-assisted remote attackers to execute arbitrary FTP commands via a cra…

Fix: after 10.4.8
Fix from $1,600 2006-11-30