Vulnerabilities > Apple > MAC OS X > 10.5.2

DATE CVE VULNERABILITY TITLE RISK
2008-03-18 CVE-2008-0060 Code Injection vulnerability in Apple mac OS X and mac OS X Server
Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML or JavaScript into a topic list page, as demonstrated using a help:runscript link.
network
apple CWE-94
6.8
2008-03-18 CVE-2008-0047 Buffer Errors vulnerability in Cups 1.3.5
Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions.
network
apple cups CWE-119
critical
9.3
2008-03-18 CVE-2008-0046 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the "Set access for specific services and applications" radio button that might cause the user to believe that the button is used to restrict access only to specific services and applications, which might allow attackers to bypass intended access restrictions.
network
low complexity
apple CWE-264
5.0
2008-03-18 CVE-2008-0044 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Multiple buffer overflows in AFP Client in Apple Mac OS X 10.4.11 and 10.5.2 allow remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted afp:// URL.
network
apple CWE-119
5.8
2007-12-07 CVE-2007-6276 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows remote attackers to cause a denial of service (divide-by-zero error and daemon crash) via a crafted load balancing packet to UDP port 4112.
network
low complexity
apple CWE-189
7.8
2007-12-06 CVE-2007-5971 Resource Management Errors vulnerability in MIT Kerberos 5
Double free vulnerability in the gss_krb5int_make_seal_token_v3 function in lib/gssapi/krb5/k5sealv3.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors.
local
apple mit CWE-399
6.9
2007-12-06 CVE-2007-5901 Resource Management Errors vulnerability in MIT Kerberos 5
Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 (krb5) has unknown impact and attack vectors.
local
apple mit CWE-399
6.9
2007-11-29 CVE-2007-6166 Buffer Errors vulnerability in Apple Quicktime and Safari
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.
network
apple microsoft CWE-119
critical
9.3
2007-03-05 CVE-2007-0714 Numeric Errors vulnerability in Apple Quicktime
Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QuickTime movie with a User Data Atom (UDTA) with an Atom size field with a large value.
network
apple microsoft CWE-189
critical
9.3
2007-03-05 CVE-2007-0712 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MIDI file.
network
apple microsoft CWE-119
critical
9.3