Vulnerabilities > Apple > MAC OS X Server > High

DATE CVE VULNERABILITY TITLE RISK
2009-08-06 CVE-2009-2191 USE of Externally-Controlled Format String vulnerability in Apple mac OS X and mac OS X Server
Format string vulnerability in Login Window in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in an application name.
network
low complexity
apple CWE-134
7.5
2009-08-06 CVE-2009-2190 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
launchd in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to cause a denial of service (individual service outage) by making many connections to an inetd-based launchd service.
network
low complexity
apple CWE-399
7.8
2009-08-06 CVE-2009-0151 Multiple Security vulnerability in Apple Mac OS X 2009-003
The screen saver in Dock in Apple Mac OS X 10.5 before 10.5.8 does not prevent four-finger Multi-Touch gestures, which allows physically proximate attackers to bypass locking and "manage applications or use Expose" via unspecified vectors.
local
low complexity
apple
7.2
2009-06-16 CVE-2009-1719 Code Injection vulnerability in SUN JRE 1.5.0/1.5.011B03
The Aqua Look and Feel for Java implementation in Java 1.5 on Mac OS X 10.5 allows remote attackers to execute arbitrary code via a call to the undocumented apple.laf.CColourUIResource constructor with a crafted value in the first argument, which is dereferenced as a pointer.
network
low complexity
apple sun CWE-94
7.5
2009-06-09 CVE-2009-0949 Use of Uninitialized Resource vulnerability in multiple products
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.
network
low complexity
apple canonical debian opensuse suse CWE-908
7.5
2009-05-13 CVE-2009-0152 Cleartext Storage of Sensitive Information vulnerability in Apple mac OS X and mac OS X Server
iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communication in certain circumstances that are inconsistent with the Require SSL setting, which allows remote attackers to obtain sensitive information by sniffing the network.
network
low complexity
apple CWE-312
7.5
2009-05-13 CVE-2008-1517 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
Array index error in the xnu (Mach) kernel in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (system shutdown) via unspecified vectors related to workqueues.
local
low complexity
apple CWE-20
7.2
2009-04-17 CVE-2009-0946 Integer Overflow OR Wraparound vulnerability in multiple products
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
7.5
2009-04-02 CVE-2009-1238 Race Condition vulnerability in Apple mac OS X and mac OS X Server
Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS code path in multiple threads, which is problematic because of lack of mutex locking for an unspecified global variable.
local
low complexity
apple CWE-362
7.2
2009-04-02 CVE-2009-1235 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls.
local
low complexity
apple CWE-264
7.2