Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mac Os X HIGH 7.5
CVE-2003-0378

The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to …

Fix: after 10.2
Fix from $1,950 2003-06-16
Mac Os X HIGH 7.5
CVE-2003-0242

IPSec in Mac OS X before 10.2.6 does not properly handle certain incoming security policies that match by port, which could allow traffic that is not…

Fix: 10.2.6+
Fix from $1,950 2003-06-09
Safari MEDIUM 5.0
CVE-2003-0355

Safari 1.0 Beta 2 (v73) and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof …

Mitigation only
Fix from $1,600 2003-06-09
Mac Os X HIGH 7.2
CVE-2003-0171

DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitr…

Mitigation only
Fix from $1,950 2003-05-05
Mac Os X MEDIUM 6.4
CVE-2003-0198

Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files.

Mitigation only
Fix from $1,600 2003-05-05
Darwin Streaming Server HIGH 7.5
CVE-2003-0050EPSS 69%

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2003-03-07
Darwin Streaming Server HIGH 7.5
CVE-2003-0054

Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request…

Mitigation only
Fix from $1,950 2003-03-07
Quicktime Darwin Mp3 Broadcaster HIGH 7.5
CVE-2003-0055

Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remo…

Mitigation only
Fix from $1,950 2003-03-07
Darwin Streaming Server MEDIUM 5.0
CVE-2003-0051

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physic…

Mitigation only
Fix from $1,600 2003-03-07
Darwin Streaming Server MEDIUM 5.0
CVE-2003-0052

parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary di…

Mitigation only
Fix from $1,600 2003-03-07
Mac Os X HIGH 7.5
CVE-2003-0049

Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.

Patch available
Fix from $1,950 2003-03-03
Mac Os X HIGH 7.2
CVE-2003-0088

TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certa…

Patch available
Fix from $1,950 2003-03-03
Tcp Ip Configuration Utility HIGH 7.5
CVE-2002-2373

The default configuration of the TCP/IP printer configuration utility in Apple LaserWriter 12/640 PS printer contains a blank Telnet password, which …

Mitigation only
Fix from $1,950 2002-12-31
Terminal HIGH 7.2
CVE-2002-1898

Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a telnet:// link, which is exec…

Fix: 1.3.1+
Fix from $1,950 2002-12-31
Mac Os X MEDIUM 5.0
CVE-2002-2326

The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext whe…

Mitigation only
Fix from $1,600 2002-12-31
Mac Os X MEDIUM 5.0
CVE-2002-1267

Mac OS X 10.2.2 allows remote attackers to cause a denial of service by accessing the CUPS Printing Web Administration utility, aka "CUPS Printing We…

Patch available
Fix from $1,600 2002-12-11
Mac Os X HIGH 7.5
CVE-2002-0676

SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitra…

No fix yet
Fix from $1,950 2002-07-11
Mac Os Runtime For Java HIGH 7.5
CVE-2001-1480

Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard.

Patch available
Fix from $1,950 2001-12-31
Claris Emailer HIGH 7.5
CVE-2001-1531

Buffer overflow in Claris Emailer 2.0v2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an email attachm…

Mitigation only
Fix from $1,950 2001-12-31
Personal Web Sharing MEDIUM 5.0
CVE-2001-1575

Apple Personal Web Sharing (PWS) 1.1, 1.5, and 1.5.5, when Web Sharing authentication is enabled, allows remote attackers to cause a denial of servic…

Mitigation only
Fix from $1,600 2001-12-31
Mac Os X HIGH 7.5
CVE-2001-0720

Internet Explorer 5.1 for Macintosh on Mac OS X allows remote attackers to execute arbitrary commands by causing a BinHex or MacBinary file type to b…

Mitigation only
Fix from $1,950 2001-12-06
Mac Os X HIGH 7.2
CVE-2001-1447

NetInfo Manager for Mac OS X 10.0 through 10.1 allows local users to gain root privileges by opening applications using the (1) "recent items" and (2…

Patch available
Fix from $1,950 2001-10-17
Personal Web Sharing MEDIUM 5.0
CVE-2001-0649EPSS 5%

Personal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request.

No fix yet
Fix from $1,600 2001-09-20
Mac Os X HIGH 7.5
CVE-2001-1446

Find-By-Content in Mac OS X 10.0 through 10.0.4 creates world-readable index files named .FBCIndex in every directory, which allows remote attackers …

Mitigation only
Fix from $1,950 2001-09-11
macOS HIGH 7.2
CVE-2001-0102

"Multiple Users" Control Panel in Mac OS 9 allows Normal users to gain Owner privileges by removing the Users & Groups Data File, which effectively r…

No fix yet
Fix from $1,950 2001-02-12
Mac Os Runtime For Java HIGH 10.0
CVE-2000-0563

The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site o…

Fix: after 2.1
Fix from $1,950 2000-10-20
Appleshare MEDIUM 5.0
CVE-2000-0346

AppleShare IP 6.1 and later allows a remote attacker to read potentially sensitive information via an invalid range request to the web server.

Mitigation only
Fix from $1,600 2000-05-02
Webobjects MEDIUM 5.0
CVE-2000-0299EPSS 5%

Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request wi…

Mitigation only
Fix from $1,600 2000-04-04
macOS MEDIUM 5.0
CVE-2000-0041

Macintosh systems generate large ICMP datagrams in response to malformed datagrams, allowing them to be used as amplifiers in a flood attack.

Mitigation only
Fix from $1,600 1999-12-28
Ichat Server MEDIUM 5.0
CVE-1999-0897

iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.

Mitigation only
Fix from $1,600 1998-09-09