Vulnerabilities > Apple > MAC OS X > 10.3.5

DATE CVE VULNERABILITY TITLE RISK
2007-05-29 CVE-2007-2388 Permissions, Privileges, and Access Controls vulnerability in Apple Quicktime 7.1.6
Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations.
network
apple microsoft CWE-264
critical
9.3
2007-05-24 CVE-2007-0753 USE of Externally-Controlled Format String vulnerability in Apple mac OS X and mac OS X Server
Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter.
local
low complexity
apple CWE-134
7.2
2007-05-24 CVE-2007-0751 Multiple Security vulnerability in Apple Mac OS X 2007-005
A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp, which might allow local users to cause a denial of service, related to the find command.
local
low complexity
apple
2.1
2007-04-24 CVE-2007-0742 Multiple Security vulnerability in Apple Mac OS X 2007-004
The WebFoundation framework in Apple Mac OS X 10.3.9 and earlier allows subdomain cookies to be accessed by the parent domain, which allows remote attackers to obtain sensitive information.
network
low complexity
apple
7.8
2007-04-24 CVE-2007-0729 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X, mac OS X Preview.App and mac OS X Server
Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which allows local users to gain privileges by setting unspecified environment variables.
local
low complexity
apple CWE-264
7.2
2007-03-13 CVE-2007-0720 The CUPS service on multiple platforms allows remote attackers to cause a denial of service (service hang) via a "partially-negotiated" SSL connection, which prevents other requests from being accepted.
network
low complexity
cups apple
5.0
2007-01-23 CVE-2007-0430 Denial-Of-Service vulnerability in Mac OS X
The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial of service (memory corruption) via a large mappingCount value.
local
low complexity
apple
4.9
2006-12-31 CVE-2006-6906 Local Security vulnerability in Mac OS X
Unspecified vulnerability in the Bluetooth stack on Mac OS 10.4.7 and earlier has unknown impact and local attack vectors, related to "Mach Exception Handling", a different issue than CVE-2006-6900.
local
low complexity
apple
7.2
2006-12-20 CVE-2006-6652 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Buffer overflow in the glob implementation (glob.c) in libc in NetBSD-current before 20050914, NetBSD 2.* and 3.* before 20061203, and Apple Mac OS X before 2007-004, as used by the FTP daemon and tnftpd, allows remote authenticated users to execute arbitrary code via a long pathname that results from path expansion.
network
low complexity
apple netbsd CWE-119
critical
9.0
2006-11-30 CVE-2006-6173 Local Memory Corruption vulnerability in Apple Mac OS X Shared_Region_Make_Private_Np Kernel Function
Buffer overflow in the shared_region_make_private_np function in vm/vm_unix.c in Mac OS X 10.4.6 and earlier allows local users to execute arbitrary code via (1) a small range count, which causes insufficient memory allocation, or (2) a large number of ranges in the shared_region_make_private_np_args parameter.
local
low complexity
apple
7.2