Vulnerability index

Browse CVEs

6,692 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2005-0974 Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments. Mac Os X Mitigation only Fix from $1,9502005-05-12 HIGH 7.5 CVE-2005-1332 Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files wi… Mac Os X Mitigation only Fix from $1,9502005-05-04 HIGH 7.5 CVE-2005-1337 Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges vi… Mac Os X Mitigation only Fix from $1,9502005-05-04 HIGH 7.5 CVE-2005-1339 lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name. Mac Os X Mitigation only Fix from $1,9502005-05-04 HIGH 7.5 CVE-2005-1340 The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the prox… Mac Os X Patch available Fix from $1,9502005-05-04 HIGH 7.5 CVE-2005-1342EPSS 5% The x-man-page: URI handler for Apple Terminal 1.4.4 in Mac OS X 10.3.9 does not cleanse terminal escape sequences, which allows remote attackers to … Terminal Patch available Fix from $1,9502005-05-04 HIGH 7.2 CVE-2005-0594 Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code. Mac Os X Server Mitigation only Fix from $1,9502005-05-04 HIGH 7.2 CVE-2005-1335 Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper pro… Mac Os X Mitigation only Fix from $1,9502005-05-04 MEDIUM 5.1 CVE-2005-1331 The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different t… Applescript Patch available Fix from $1,6002005-05-04 MEDIUM 5.1 CVE-2005-1341 Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences. Terminal Patch available Fix from $1,6002005-05-04 MEDIUM 5.0 CVE-2005-1333EPSS 7% Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitr… Mac Os X Patch available Fix from $1,6002005-05-04 HIGH 7.2 CVE-2005-1343 Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id… Mac Os X Patch available Fix from $1,9502005-05-03 HIGH 7.6 CVE-2005-0970 Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the intended design, which may allow atta… Mac Os X Mitigation only Fix from $1,9502005-05-02 HIGH 7.5 CVE-2005-0043EPSS 69% Buffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files. Itunes Patch available Fix from $1,9502005-05-02 HIGH 7.5 CVE-2005-0126 ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC color profiles that modify the heap. Mac Os X Patch available Fix from $1,9502005-05-02 HIGH 7.2 CVE-2005-0125 The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2… Mac Os X Patch available Fix from $1,9502005-05-02 MEDIUM 5.0 CVE-2005-0127 Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being… Mac Os X Patch available Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-0234 The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that ar… Safari No fix yet Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-0289 Apple AirPort Express prior to 6.1.1 and Extreme prior to 5.5.1, configured as a Wireless Data Service (WDS), allows remote attackers to cause a deni… Airport Express after 6.1 Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-0340 Integer signedness error in Apple File Service (AFP Server) allows remote attackers to cause a denial of service (application crash) via a negative U… Afp Server Patch available Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-0976 AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrar… Safari No fix yet Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-1106 PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximu… Quicktime Pictureviewer Mitigation only Fix from $1,6002005-05-02 HIGH 7.2 CVE-2005-0716 Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execut… Mac Os X Mitigation only Fix from $1,9502005-03-21 HIGH 7.5 CVE-2004-1021 iCal before 1.5.4 on Mac OS X 10.2.3, and other later versions, does not alert the user when handling calendars that use alarms, which allows attacke… Ical Mitigation only Fix from $1,9502005-03-01 HIGH 10.0 CVE-2004-0962 Apple Remote Desktop Client 1.2.4 executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application, which a… Apple Remote Desktop Mitigation only Fix from $1,9502005-02-09 HIGH 7.5 CVE-2004-0921 AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modifi… Quicktime Patch available Fix from $1,9502005-01-27 MEDIUM 5.0 CVE-2004-0922 AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only … Quicktime Patch available Fix from $1,6002005-01-27 MEDIUM 5.0 CVE-2004-0925 Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allow… Mac Os X Patch available Fix from $1,6002005-01-27 HIGH 7.5 CVE-2004-1122 Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialo… Safari Mitigation only Fix from $1,9502005-01-10 HIGH 7.5 CVE-2004-1314 Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but res… Safari Mitigation only Fix from $1,9502005-01-10