Vulnerabilities > Apple > Ichat

DATE CVE VULNERABILITY TITLE RISK
2007-08-03 CVE-2007-3748 Multiple Security vulnerability in Apple Mac OS X 2007-007
Buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in iChat on Apple Mac OS X 10.3.9 and 10.4.10 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet.
5.4
2007-08-03 CVE-2007-3747 Multiple Security vulnerability in Apple Mac OS X 2007-007
The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not restrict object instantiation and manipulation to valid heap addresses, which allows remote attackers to execute arbitrary code via a crafted applet.
network
apple
6.8
2007-08-03 CVE-2007-3746 Multiple Security vulnerability in Apple Mac OS X 2007-007
The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not properly check the bounds of heap read and write operations, which allows remote attackers to execute arbitrary code via a crafted applet.
network
apple
6.8
2007-02-16 CVE-2007-0710 Resource Management Errors vulnerability in Apple Ichat
The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614.
local
low complexity
apple CWE-399
2.1
2007-01-31 CVE-2007-0614 Remote Denial of Service vulnerability in Apple Ichat, Instant Message Framework and mac OS X
The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.
network
low complexity
apple
7.8
2007-01-31 CVE-2007-0613 Remote Denial of Service vulnerability in Apple Ichat, Instant Message Framework and Mdnsresponder
The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entries when adding newly discovered available contacts, which allows remote attackers to cause a denial of service (disrupted communication) via a flood of duplicate _presence._tcp mDNS queries.
network
low complexity
apple
5.0
2007-01-23 CVE-2007-0021 Remote Format String vulnerability in Apple Ichat 3.1.6
Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.
network
low complexity
apple
7.5
2004-12-23 CVE-2004-0873 Unspecified vulnerability in Apple Ichat and Ichat AV
Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a "link" that references the program.
network
low complexity
apple
7.5