Vulnerabilities > Apple > MAC OS X > 10.3

DATE CVE VULNERABILITY TITLE RISK
2006-04-21 CVE-2006-1982 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remote attackers to execute arbitrary code via crafted TIFF images.
network
low complexity
apple CWE-119
7.5
2006-03-14 CVE-2006-1220 Local Heap Overflow vulnerability in Apple Mac OS X Kernel MACH_MSG_SEND
Integer overflow in the mach_msg_send function in the kernel for Mac OS X might allow local users to execute arbitrary code via unknown attack vectors related to a large message header size, which leads to a heap-based buffer overflow.
local
low complexity
apple
4.6
2006-03-06 CVE-2006-0387 Multiple vulnerability in Apple Mac OS X Security Update 2006-001
Stack-based buffer overflow in Safari in Mac OS X 10.4.5 and earlier, and 10.3.9 and earlier, allows remote attackers to execute arbitrary code via unspecified vectors involving a web page with crafted JavaScript, a different vulnerability than CVE-2005-4504.
network
low complexity
apple
6.4
2006-03-03 CVE-2006-0388 Code Injection vulnerability in Apple mac OS X and mac OS X Server
Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources.
local
high complexity
apple CWE-94
2.6
2006-03-03 CVE-2006-0386 Multiple vulnerability in Apple Mac OS X Security Update 2006-001
FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.
local
low complexity
apple
1.7
2006-03-02 CVE-2006-0384 Multiple vulnerability in Apple Mac OS X Security Update 2006-001
automount in Mac OS X 10.4.5 and earlier allows remote file servers to cause a denial of service (unresponsiveness) or execute arbitrary code via unspecified vectors that cause automount to "mount file systems with reserved names".
network
low complexity
apple
7.5
2006-03-02 CVE-2006-0383 Multiple vulnerability in Apple Mac OS X Security Update 2006-001
IPSec when used with VPN networks in Mac OS X 10.4 through 10.4.5 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving the "incorrect handling of error conditions".
network
low complexity
apple
5.0
2005-12-31 CVE-2005-2714 Link Following vulnerability in Apple mac OS X and mac OS X Server
passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to overwrite arbitrary files via a symlink attack on the .pwtmp.[PID] temporary file.
local
low complexity
apple CWE-59
6.8
2005-12-31 CVE-2005-2713 Multiple vulnerability in Apple Mac OS X Security Update 2006-001
passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to create arbitrary world-writable files as root by specifying an alternate file in the password database option.
local
low complexity
apple
6.8
2005-12-31 CVE-2005-2194 TCP/IP Remote Denial Of Service vulnerability in Apple Mac OSX
Unspecified vulnerability in the Apple Mac OS X kernel before 10.4.2 allows remote attackers to cause a denial of service (kernel panic) via a crafted TCP packet, possibly related to source routing or loose source routing.
network
low complexity
apple
5.0