Vulnerabilities > Apple > MAC OS X Server > 10.5.0

DATE CVE VULNERABILITY TITLE RISK
2009-08-06 CVE-2009-1723 Multiple Security vulnerability in Apple Mac OS X 2009-003
CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in certain 302 redirection scenarios, which makes it easier for remote attackers to trick a user into visiting an arbitrary https web site by leveraging an open redirect vulnerability, a different issue than CVE-2009-2062.
network
apple
4.3
2009-08-06 CVE-2009-0151 Multiple Security vulnerability in Apple Mac OS X 2009-003
The screen saver in Dock in Apple Mac OS X 10.5 before 10.5.8 does not prevent four-finger Multi-Touch gestures, which allows physically proximate attackers to bypass locking and "manage applications or use Expose" via unspecified vectors.
local
low complexity
apple
7.2
2009-06-16 CVE-2009-1719 Code Injection vulnerability in SUN JRE 1.5.0/1.5.011B03
The Aqua Look and Feel for Java implementation in Java 1.5 on Mac OS X 10.5 allows remote attackers to execute arbitrary code via a call to the undocumented apple.laf.CColourUIResource constructor with a crafted value in the first argument, which is dereferenced as a pointer.
network
low complexity
apple sun CWE-94
7.5
2009-06-09 CVE-2009-0949 Use of Uninitialized Resource vulnerability in multiple products
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.
network
low complexity
apple canonical debian opensuse suse CWE-908
7.5
2009-06-05 CVE-2009-1717 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted size value in a CSI[4 xterm resize escape sequence that triggers a heap-based buffer overflow.
network
apple CWE-189
6.8
2009-05-13 CVE-2009-0945 Code Injection vulnerability in Apple Safari
Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4) SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object, which triggers memory corruption.
network
apple microsoft CWE-94
critical
9.3
2009-05-13 CVE-2009-0944 Code Injection vulnerability in Apple mac OS X and mac OS X Server
The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a file that triggers memory corruption.
network
apple CWE-94
6.8
2009-05-13 CVE-2009-0943 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.
network
apple CWE-20
6.8
2009-05-13 CVE-2009-0942 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.
network
apple CWE-20
6.8
2009-05-13 CVE-2009-0162 Cross-Site Scripting vulnerability in Apple Safari
Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote attackers to inject arbitrary web script or HTML via a crafted feed: URL.
4.3