Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Safari MEDIUM 5.0
CVE-2006-1552

Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image…

Patch available
Fix from $1,600 2006-03-31
Itunes MEDIUM 6.8
CVE-2006-1249EPSS 6%

Integer overflow in Apple QuickTime Player 7.0.3 and 7.0.4 and iTunes 6.0.1 and 6.0.2 allows remote attackers to execute arbitrary code via a FlashPi…

Mitigation only
Fix from $1,600 2006-03-19
Mac Os X HIGH 7.5
CVE-2006-0397

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into openi…

Patch available
Fix from $1,950 2006-03-14
Mac Os X HIGH 7.5
CVE-2006-0398

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into openi…

Patch available
Fix from $1,950 2006-03-14
Mac Os X HIGH 7.5
CVE-2006-0399

Unspecified vulnerability in Safari, LaunchServices, and/or CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows attackers to trick a user into openi…

Patch available
Fix from $1,950 2006-03-14
Mac Os X HIGH 7.5
CVE-2006-0400

CoreTypes in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to bypass the same-origin policy and execute Javascript in other domains via un…

Patch available
Fix from $1,950 2006-03-14
Mac Os X MEDIUM 5.1
CVE-2006-0396EPSS 11%

Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary…

Patch available
Fix from $1,600 2006-03-14
Mac Os X MEDIUM 6.4
CVE-2006-0387EPSS 8%

Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via u…

Patch available
Fix from $1,600 2006-03-06
Mac Os X HIGH 7.5
CVE-2006-0384

automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via uns…

Patch available
Fix from $1,950 2006-03-02
Mac Os X MEDIUM 5.0
CVE-2006-0383

IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspec…

Patch available
Fix from $1,600 2006-03-02
Mac Os X MEDIUM 5.1
CVE-2006-0848EPSS 58%

The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by t…

No fix yet
Fix from $1,600 2006-02-22
Mac Os X MEDIUM 6.8
CVE-2005-2713

passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to create arbitrary world-writable files as…

Patch available
Fix from $1,600 2005-12-31
Mac Os X MEDIUM 6.8
CVE-2005-2714

passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to overwrite arbitrary files via a symlink …

Patch available
Fix from $1,600 2005-12-31
Mac Os X MEDIUM 6.5
CVE-2005-3712

Heap-based buffer overflow in rsync in Mac OS X 10.4 through 10.4.5 allows remote authenticated users to execute arbitrary code via long extended att…

Patch available
Fix from $1,600 2005-12-31
Mac Os X MEDIUM 6.4
CVE-2005-3706

Heap-based buffer overflow in LibSystem in Mac OS X 10.4 through 10.4.5 allows context-dependent attackers to execute arbitrary code by causing an ap…

Patch available
Fix from $1,600 2005-12-31
Mac Os X MEDIUM 5.0
CVE-2005-2194

Unspecified vulnerability in the Apple Mac OS X kernel before 10.4.2 allows remote attackers to cause a denial of service (kernel panic) via a crafte…

Fix: after 10.4.1
Fix from $1,600 2005-12-31
Airport Express MEDIUM 5.0
CVE-2005-3714

The network interface for Apple AirPort Express 6.x before Firmware Update 6.3, and AirPort Extreme 5.x before Firmware Update 5.7, allows remote att…

Patch available
Fix from $1,600 2005-12-31
Safari MEDIUM 5.0
CVE-2005-4678

Apple Safari 2.0.2 (aka 416.12) allows remote attackers to spoof the URL in the status bar via the title in an image in a link to a trusted site with…

No fix yet
Fix from $1,600 2005-12-31
Safari HIGH 7.8
CVE-2005-4504EPSS 12%

The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote…

Fix: after 1.4
Fix from $1,950 2005-12-22
Mac Os X Server HIGH 7.5
CVE-2005-4217

Perl in Apple Mac OS X Server 10.3.9 does not properly drop privileges when using the "$<" variable to set uid, which allows attackers to gain privil…

Mitigation only
Fix from $1,950 2005-12-14
Itunes HIGH 7.5
CVE-2005-4092EPSS 9%

Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to caus…

Mitigation only
Fix from $1,950 2005-12-08
Mac Os X HIGH 7.5
CVE-2005-2757

Heap-based buffer overflow in CoreFoundation in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to execute arbitrary code via un…

Patch available
Fix from $1,950 2005-12-01
Mac Os X HIGH 7.5
CVE-2005-3705

Heap-based buffer overflow in WebKit in Mac OS X and OS X Server 10.3.9 and 10.4.3, as used in applications such as Safari, allows remote attackers t…

Patch available
Fix from $1,950 2005-12-01
Mac Os X Server HIGH 7.2
CVE-2005-3701

Unspecified vulnerability in passwordserver in Mac OS X Server 10.3.9 and 10.4.3, when creating an Open Directory master server, allows local users t…

Patch available
Fix from $1,950 2005-12-01
Mac Os X MEDIUM 5.0
CVE-2005-3702

Safari in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows remote attackers to cause files to be downloaded to locations outside the download direct…

Patch available
Fix from $1,600 2005-12-01
Mac Os X MEDIUM 5.0
CVE-2005-3704

System log server in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to spoof syslog messages in log files by injecting various …

Patch available
Fix from $1,600 2005-12-01
Safari HIGH 7.8
CVE-2005-3897

Apple Safari 2.0.2 allows remote attackers to cause a denial of service (system slowdown) via a Javascript BODY onload event that calls the window fu…

Mitigation only
Fix from $1,950 2005-11-29
Itunes HIGH 7.2
CVE-2005-2938

Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges…

Mitigation only
Fix from $1,950 2005-11-18
Quicktime HIGH 7.5
CVE-2005-2743

The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, …

Patch available
Fix from $1,950 2005-10-26
Mac Os X HIGH 7.2
CVE-2005-2741

Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should…

Patch available
Fix from $1,950 2005-10-26