Vulnerabilities > Apple > MAC OS X > 10.3

DATE CVE VULNERABILITY TITLE RISK
2009-04-02 CVE-2009-1238 Race Condition vulnerability in Apple mac OS X and mac OS X Server
Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS code path in multiple threads, which is problematic because of lack of mutex locking for an unspecified global variable.
local
low complexity
apple CWE-362
7.2
2009-04-02 CVE-2009-1237 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a denial of service (kernel memory consumption) via a crafted (1) SYS_add_profil or (2) SYS___mac_getfsstat system call.
local
low complexity
apple CWE-399
4.9
2009-04-02 CVE-2009-1236 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via a ZIP NOTIFY (aka ZIPOP_NOTIFY) packet that overwrites a certain ifPort structure member.
network
low complexity
apple CWE-119
critical
10.0
2009-04-02 CVE-2009-1235 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls.
local
low complexity
apple CWE-264
7.2
2008-12-17 CVE-2008-4237 Multiple Security vulnerability in RETIRED: Apple Mac OS X 2008-008
Managed Client in Apple Mac OS X before 10.5.6 sometimes misidentifies a system when installing per-host configuration settings, which allows context-dependent attackers to have an unspecified impact by leveraging unintended settings, as demonstrated by the screen saver lock setting.
network
low complexity
apple
critical
10.0
2008-12-17 CVE-2008-4236 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
Apple Type Services (ATS) in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to cause a denial of service (infinite loop) via a crafted embedded font in a PDF file.
network
apple CWE-399
7.1
2008-12-17 CVE-2008-4234 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers to execute arbitrary code via an executable file with the content type indicating no application association for the file, which does not trigger a "potentially unsafe" warning message.
network
apple CWE-264
critical
9.3
2008-12-17 CVE-2008-4224 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
UDF in Apple Mac OS X before 10.5.6 allows user-assisted attackers to cause a denial of service (system crash) via a malformed UDF volume in a crafted ISO file.
network
apple CWE-20
7.1
2008-12-17 CVE-2008-4222 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
natd in network_cmds in Apple Mac OS X before 10.5.6, when Internet Sharing is enabled, allows remote attackers to cause a denial of service (infinite loop) via a crafted TCP packet.
network
apple CWE-399
7.1
2008-12-17 CVE-2008-4221 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
The strptime API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted date string, related to improper memory allocation.
network
low complexity
apple CWE-399
critical
10.0