Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Safari MEDIUM 5.0
CVE-2005-2524

Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render …

Patch available
Fix from $1,600 2005-10-26
Mac Os X MEDIUM 5.0
CVE-2005-2745

Mail.app in Mail for Apple Mac OS X 10.3.9, when using Kerberos 5 for SMTP authentication, can include uninitialized memory in a message, which might…

Patch available
Fix from $1,600 2005-10-26
Mac Os X MEDIUM 5.0
CVE-2005-2746

Mail.app in Mail for Apple Mac OS X 10.3.9 and 10.4.2 includes message contents when using auto-reply rules, which could cause Mail.app to include de…

Patch available
Fix from $1,600 2005-10-26
Mac Os X HIGH 7.5
CVE-2005-2747

Buffer overflow in ImageIO for Apple Mac OS X 10.4.2, as used by applications such as WebCore and Safari, allows remote attackers to execute arbitrar…

Patch available
Fix from $1,950 2005-10-25
Mac Os X MEDIUM 5.1
CVE-2005-2744

Buffer overflow in QuickDraw Manager for Apple OS X 10.3.9 and 10.4.2, as used by applications such as Safari, Mail, and Finder, allows remote attack…

Patch available
Fix from $1,600 2005-10-25
Safari MEDIUM 5.0
CVE-2005-3018

Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL.

No fix yet
Fix from $1,600 2005-09-21
Mac Os X HIGH 10.0
CVE-2005-2511

Unknown vulnerability in Mac OS X 10.4.2 and earlier, when using Kerberos authentication with LDAP, allows attackers to gain access to a root Termina…

Patch available
Fix from $1,950 2005-08-19
Mac Os X HIGH 7.6
CVE-2005-2501

Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Fo…

Patch available
Fix from $1,950 2005-08-19
Mac Os X HIGH 7.5
CVE-2005-2505

Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that use…

Patch available
Fix from $1,950 2005-08-19
Mac Os X Server HIGH 7.5
CVE-2005-2507EPSS 6%

Buffer overflow in Directory Services in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.

Patch available
Fix from $1,950 2005-08-19
Mac Os X HIGH 7.5
CVE-2005-2514

Buffer overflow in ping in Mac OS X 10.3.9 allows local users to execute arbitrary code.

Patch available
Fix from $1,950 2005-08-19
Safari HIGH 7.5
CVE-2005-2516

Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security ch…

Patch available
Fix from $1,950 2005-08-19
Mac Os X HIGH 7.5
CVE-2005-2518

Buffer overflow in servermgrd in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.

Patch available
Fix from $1,950 2005-08-19
Mac Os X HIGH 7.2
CVE-2005-2504

The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No" even when the user has selected the "Require pair…

Patch available
Fix from $1,950 2005-08-19
Mac Os X HIGH 7.2
CVE-2005-2519

slpd in Directory Services in Mac OS X 10.3.9 creates insecure temporary files as root, which allows local users to gain privileges.

Patch available
Fix from $1,950 2005-08-19
Mac Os X MEDIUM 5.1
CVE-2005-2502

Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2, as used in applications such as TextEdit, allows external user-assisted attackers to execut…

Mitigation only
Fix from $1,600 2005-08-19
Safari MEDIUM 5.1
CVE-2005-2522

Safari in WebKit in Mac OS X 10.4 to 10.4.2 directly accesses URLs within PDF files without the normal security checks, which allows remote attackers…

Patch available
Fix from $1,600 2005-08-19
Mac Os X MEDIUM 5.0
CVE-2005-2506

Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) …

Patch available
Fix from $1,600 2005-08-19
Mac Os X MEDIUM 5.0
CVE-2005-2513

Unknown vulnerability in HItoolbox for Mac OS X 10.4.2 allows VoiceOver services to read secure input fields.

Patch available
Fix from $1,600 2005-08-19
Safari MEDIUM 5.0
CVE-2005-2594

Apple Safari 1.3 (132) on Mac OS X 1.3.9 allows remote attackers to cause a denial of service (crash) via certain Javascript, possibly involving a fu…

No fix yet
Fix from $1,600 2005-08-17
Darwin Streaming Server MEDIUM 5.0
CVE-2005-2195

Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename cont…

Fix: after 5.5
Fix from $1,600 2005-07-18
Afp Server HIGH 7.5
CVE-2005-1721

Buffer overflow in the legacy client support for AFP Server for Mac OS X 10.4.1 allows attackers to execute arbitrary code.

Mitigation only
Fix from $1,950 2005-06-16
Mac Os X HIGH 7.2
CVE-2005-1722

Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root se…

Mitigation only
Fix from $1,950 2005-06-16
Mac Os X HIGH 7.5
CVE-2005-1474

Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than C…

Patch available
Fix from $1,950 2005-06-13
Mac Os X HIGH 7.5
CVE-2005-1933

Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget …

No fix yet
Fix from $1,950 2005-06-13
Mac Os X Server HIGH 7.5
CVE-2005-1723

LaunchServices in Apple Mac OS X 10.4.x up to 10.4.1 does not properly mark file extensions and MIME types as unsafe if an Apple Uniform Type Identif…

Patch available
Fix from $1,950 2005-06-08
Mac Os X Server HIGH 7.5
CVE-2005-1724

NFS on Apple Mac OS X 10.4.x up to 10.4.1 does not properly obey the -network or -mask flags for a filesystem and exports it to everyone, which allow…

Patch available
Fix from $1,950 2005-06-08
Keynote MEDIUM 5.0
CVE-2005-1408

Apple Keynote 2.0 and 2.0.1 allows remote attackers to read arbitrary files via the keynote: URI handler in a crafted Keynote presentation.

Patch available
Fix from $1,600 2005-05-26
Itunes HIGH 7.5
CVE-2005-1248EPSS 5%

Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.

Patch available
Fix from $1,950 2005-05-16
Mac Os X HIGH 7.2
CVE-2005-0972

Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.

Mitigation only
Fix from $1,950 2005-05-12