Vulnerabilities > Apple > MAC OS X > 10.4.3

DATE CVE VULNERABILITY TITLE RISK
2008-12-17 CVE-2008-4218 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Multiple integer overflows in the kernel in Apple Mac OS X before 10.5.6 on Intel platforms allow local users to gain privileges via a crafted call to (1) i386_set_ldt or (2) i386_get_ldt.
local
low complexity
apple CWE-189
7.2
2008-12-17 CVE-2008-4217 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Integer signedness error in BOM in Apple Mac OS X before 10.5.6 allows remote attackers to execute arbitrary code via the headers in a crafted CPIO archive, leading to a stack-based buffer overflow.
network
apple CWE-189
critical
9.3
2008-11-21 CVE-2008-5183 NULL Pointer Dereference vulnerability in multiple products
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference.
network
low complexity
apple opensuse debian CWE-476
7.5
2008-08-01 CVE-2008-3438 Download of Code Without Integrity Check vulnerability in Apple mac OS X
Apple Mac OS X does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
network
high complexity
apple CWE-494
8.1
2008-07-01 CVE-2008-2314 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically proximate attackers to gain access to a locked session in (1) sleep mode or (2) screen saver mode via unspecified vectors.
local
apple CWE-264
4.4
2008-07-01 CVE-2008-2313 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local users to gain privileges by inserting a Trojan horse file into this directory.
local
low complexity
apple CWE-264
4.6
2008-07-01 CVE-2008-2311 Race Condition vulnerability in Apple mac OS X and mac OS X Server
Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a downloaded file.
network
high complexity
apple CWE-362
7.6
2008-07-01 CVE-2008-2310 USE of Externally-Controlled Format String vulnerability in Apple mac OS X and mac OS X Server
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.
network
apple CWE-134
6.8
2008-07-01 CVE-2008-2309 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5.
network
apple CWE-264
6.8
2008-07-01 CVE-2008-2308 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms allows local users to gain privileges or cause a denial of service (memory corruption and application crash) by resolving an alias that contains crafted AFP volume mount information.
local
low complexity
apple CWE-264
4.6