Vulnerabilities > Apple > MAC OS X > 10.3

DATE CVE VULNERABILITY TITLE RISK
2011-10-14 CVE-2011-3227 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
libsecurity in Apple Mac OS X before 10.7.2 does not properly handle errors during processing of a nonstandard extension in a Certificate Revocation list (CRL), which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) a crafted (1) web site or (2) e-mail message.
network
apple CWE-20
6.8
2011-10-14 CVE-2011-3224 Multiple Security vulnerability in RETIRED: Apple Mac OS X Prior to 10.7.2
The User Documentation component in Apple Mac OS X through 10.6.8 uses http sessions for updates to App Store help information, which allows man-in-the-middle attackers to execute arbitrary code by spoofing the http server.
network
high complexity
apple
2.6
2011-10-14 CVE-2011-3223 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLIC movie file.
network
apple CWE-119
6.8
2011-10-14 CVE-2011-3222 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Buffer overflow in QuickTime in Apple Mac OS X before 10.7.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.
network
apple CWE-119
6.8
2011-10-14 CVE-2011-3221 Code Injection vulnerability in Apple mac OS X and mac OS X Server
QuickTime in Apple Mac OS X before 10.7.2 does not properly handle the atom hierarchy in movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file.
network
apple CWE-94
6.8
2011-10-14 CVE-2011-3220 Information Exposure vulnerability in Apple mac OS X and mac OS X Server
QuickTime in Apple Mac OS X before 10.7.2 does not properly process URL data handlers in movie files, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.
network
apple CWE-200
4.3
2011-10-14 CVE-2011-3218 Cross-Site Scripting vulnerability in Apple mac OS X and mac OS X Server
The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the http server during local viewing of an exported document.
network
high complexity
apple CWE-79
2.6
2011-10-14 CVE-2011-3217 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
MediaKit in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image.
network
apple CWE-119
6.8
2011-10-14 CVE-2011-3216 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directories, which might allow local users to bypass intended permissions and delete files via an unlink system call.
local
low complexity
apple CWE-264
2.1
2011-10-14 CVE-2011-3215 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
The kernel in Apple Mac OS X before 10.7.2 does not properly prevent FireWire DMA in the absence of a login, which allows physically proximate attackers to bypass intended access restrictions and discover a password by making a DMA request in the (1) loginwindow, (2) boot, or (3) shutdown state.
local
low complexity
apple CWE-264
2.1