Vulnerabilities > Apple > MAC OS X Server > 10.4.8

DATE CVE VULNERABILITY TITLE RISK
2007-08-03 CVE-2007-3744 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in mDNSResponder on Apple Mac OS X 10.4.10 before 20070731 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet.
low complexity
apple CWE-119
5.8
2007-08-03 CVE-2007-2404 Multiple Security vulnerability in Apple Mac OS X 2007-007
CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context.
network
low complexity
apple
5.0
2007-07-16 CVE-2007-3798 Unchecked Return Value vulnerability in multiple products
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
network
low complexity
tcpdump canonical debian slackware freebsd apple CWE-252
critical
9.8
2007-05-24 CVE-2007-0753 USE of Externally-Controlled Format String vulnerability in Apple mac OS X and mac OS X Server
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.
local
low complexity
apple CWE-134
7.2
2007-05-24 CVE-2007-0752 Multiple Security vulnerability in Apple Mac OS X 2007-005
The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.
local
low complexity
apple
7.2
2007-05-24 CVE-2007-0751 Multiple Security vulnerability in Apple Mac OS X 2007-005
A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp, which might allow local users to cause a denial of service, related to the find command.
local
low complexity
apple
2.1
2007-05-24 CVE-2007-0750 Multiple Security vulnerability in Apple Mac OS X 2007-005
Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted PDF file.
network
apple
critical
9.3
2007-04-24 CVE-2007-0747 Multiple Security vulnerability in Apple Mac OS X 2007-004
load_webdav in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when mounting a WebDAV filesystem, which allows local users to gain privileges by setting unspecified environment variables.
local
low complexity
apple
7.2
2007-04-24 CVE-2007-0746 Multiple Security vulnerability in Apple Mac OS X 2007-004
Heap-based buffer overflow in the VideoConference framework in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via a "crafted SIP packet when initializing an audio/video conference".
network
low complexity
apple
critical
10.0
2007-04-24 CVE-2007-0744 Multiple Security vulnerability in Apple Mac OS X 2007-004
SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables.
local
low complexity
apple
7.2