Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Safari HIGH 7.5
CVE-2003-0514EPSS 5%

Apple Safari allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory trav…

No fix yet
Fix from $1,950 2004-04-15
Mac Os X HIGH 10.0
CVE-2003-1009

Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server infor…

Patch available
Fix from $1,950 2004-03-29
Mac Os X Server HIGH 7.5
CVE-2003-0601

Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, w…

Patch available
Fix from $1,950 2004-03-29
Mac Os X HIGH 7.2
CVE-2003-1006

Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute a…

Patch available
Fix from $1,950 2004-03-29
Mac Os X HIGH 7.2
CVE-2003-1011

Apple Mac OS X 10.0 through 10.2.8 allows local users with a USB keyboard to gain unauthorized access by holding down the CTRL and C keys when the sy…

Patch available
Fix from $1,950 2004-03-29
Mac Os X MEDIUM 5.0
CVE-2003-1007

AppleFileServer (AFS) in Apple Mac OS X 10.2.8 and 10.3.2 does not properly handle certain malformed requests, with unknown impact.

Patch available
Fix from $1,600 2004-03-29
Mac Os X HIGH 10.0
CVE-2004-0168

Unknown vulnerability in CoreFoundation for Mac OS X 10.3.2, related to "notification logging."

No fix yet
Fix from $1,950 2004-03-15
Mac Os X HIGH 7.5
CVE-2004-0167

DiskArbitration in Mac OS X 10.2.8 and 10.3.2 does not properly initialize writeable removable media.

No fix yet
Fix from $1,950 2004-03-15
Mac Os X MEDIUM 5.0
CVE-2004-0165

Format string vulnerability in Point-to-Point Protocol (PPP) daemon (pppd) 2.4.0 for Mac OS X 10.3.2 and earlier allows remote attackers to read arbi…

Patch available
Fix from $1,600 2004-03-15
Mac Os X MEDIUM 5.0
CVE-2004-0166

Unknown vulnerability in Safari web browser for Mac OS X 10.2.8 related to "the display of URLs in the status bar."

Patch available
Fix from $1,600 2004-03-15
Darwin Streaming Server MEDIUM 5.0
CVE-2004-0169

QuickTime Streaming Server in MacOS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (crash) via DESCRIBE requests with long …

Patch available
Fix from $1,600 2004-03-15
Mac Os X HIGH 10.0
CVE-2004-0092

Unknown vulnerability in Safari web browser in Mac OS X 10.2.8 and 10.3.2, with unknown impact.

No fix yet
Fix from $1,950 2004-03-03
Mac Os X MEDIUM 5.0
CVE-2004-0085

Unknown vulnerability in the Mail application for Mac OS X 10.1.5 and 10.2.8 with unknown impact, a different vulnerability than CVE-2004-0086.

Patch available
Fix from $1,600 2004-03-03
Mac Os X MEDIUM 5.0
CVE-2004-0086

Unknown vulnerability in the Mail application for Mac OS X 10.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2004-0085.

No fix yet
Fix from $1,600 2004-03-03
Mac Os X MEDIUM 5.0
CVE-2003-1005

The PKI functionality in Mac OS X 10.2.8 and 10.3.2 allows remote attackers to cause a denial of service (service crash) via malformed ASN.1 sequence…

Patch available
Fix from $1,600 2003-12-31
Safari MEDIUM 5.0
CVE-2003-0975

Apple Safari 1.0 through 1.1 on Mac OS X 10.3.1 and Mac OS X 10.2.8 allows remote attackers to steal user cookies from another domain via a link with…

Mitigation only
Fix from $1,600 2003-12-15
Mac Os X HIGH 7.2
CVE-2001-1411

Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.

Mitigation only
Fix from $1,950 2003-11-17
Mac Os X HIGH 7.5
CVE-2003-0871

Unknown vulnerability in QuickTime Java in Mac OS X v10.3 and Mac OS X Server 10.3 allows attackers to gain "unauthorized access to a system."

Patch available
Fix from $1,950 2003-11-03
Mac Os X HIGH 7.5
CVE-2003-0881

Mail in Mac OS X before 10.3, when configured to use MD5 Challenge Response, uses plaintext authentication if the CRAM-MD5 hashed login fails, which …

Fix: after 10.3
Fix from $1,950 2003-11-03
Mac Os X MEDIUM 5.0
CVE-2003-0882

Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attackers to determine the system's uptime via the ID …

Fix: after 10.3
Fix from $1,600 2003-11-03
Darwin Streaming Server HIGH 10.0
CVE-2003-0421

Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. …

Mitigation only
Fix from $1,950 2003-08-27
Darwin Streaming Server HIGH 10.0
CVE-2003-0426

The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allow…

No fix yet
Fix from $1,950 2003-08-27
Darwin Streaming Server HIGH 10.0
CVE-2003-0502

Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to cause a denial of service (crash) via a .. (dot dot) sequence foll…

Fix: after 4.1.3g
Fix from $1,950 2003-08-27
Darwin Streaming Server MEDIUM 5.0
CVE-2003-0422

Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via a request to view_broadcast.…

Mitigation only
Fix from $1,600 2003-08-27
Darwin Streaming Server MEDIUM 5.0
CVE-2003-0423

parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via th…

No fix yet
Fix from $1,600 2003-08-27
Darwin Streaming Server MEDIUM 5.0
CVE-2003-0424

Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to obtain the source code for scripts by appending encoded space (%20…

No fix yet
Fix from $1,600 2003-08-27
Darwin Streaming Server MEDIUM 5.0
CVE-2003-0425

Directory traversal vulnerability in Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to read arbitrary files via a ..…

No fix yet
Fix from $1,600 2003-08-27
Afp Server MEDIUM 5.0
CVE-2003-0379

Unknown vulnerability in Apple File Service (AFP Server) for Mac OS X Server, when sharing files on a UFS or re-shared NFS volume, allows remote atta…

Patch available
Fix from $1,600 2003-07-24
802.11n HIGH 7.6
CVE-2003-0270EPSS 11%

The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authe…

Mitigation only
Fix from $1,950 2003-06-16
Safari HIGH 7.5
CVE-2003-0370

Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers …

Fix: after 2.2.2
Fix from $1,950 2003-06-16