Vulnerabilities > Apple > MAC OS X > 10.5.6

DATE CVE VULNERABILITY TITLE RISK
2014-10-18 CVE-2014-4436 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X
IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a crafted application.
network
apple CWE-119
4.3
2014-10-18 CVE-2014-4435 Improper Authentication vulnerability in Apple mac OS X
The "iCloud Find My Mac" feature in Apple OS X before 10.10 does not properly enforce rate limiting of lost-mode PIN entry, which makes it easier for physically proximate attackers to obtain access via a brute-force attack involving a series of reboots.
local
apple CWE-287
4.4
2014-10-18 CVE-2014-4434 Improper Input Validation vulnerability in Apple mac OS X
The kernel in Apple OS X before 10.10 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted filename on an HFS filesystem.
local
low complexity
apple CWE-20
4.9
2014-10-18 CVE-2014-4433 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X
Heap-based buffer overflow in the kernel in Apple OS X before 10.10 allows physically proximate attackers to execute arbitrary code via crafted resource forks in an HFS filesystem.
local
low complexity
apple CWE-119
7.2
2014-10-18 CVE-2014-4432 Cryptographic Issues vulnerability in Apple mac OS X
fdesetup in Apple OS X before 10.10 does not properly display the encryption status in between a setting-update action and a reboot action, which might make it easier for physically proximate attackers to obtain cleartext data by leveraging ignorance of the reboot requirement.
local
apple CWE-310
4.7
2014-10-18 CVE-2014-4431 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X
Dock in Apple OS X before 10.10 does not properly manage the screen-lock state, which allows physically proximate attackers to view windows by leveraging an unattended workstation.
local
low complexity
apple CWE-264
2.1
2014-10-18 CVE-2014-4430 Cryptographic Issues vulnerability in Apple mac OS X
CoreStorage in Apple OS X before 10.10 retains a volume's encryption keys upon an eject action in the unlocked state, which makes it easier for physically proximate attackers to obtain cleartext data via a remount.
local
apple CWE-310
4.7
2014-10-18 CVE-2014-4428 Cryptographic Issues vulnerability in Apple mac OS X
Bluetooth in Apple OS X before 10.10 does not require encryption for HID Low Energy devices, which allows remote attackers to spoof a device by leveraging previous pairing.
5.4
2014-10-18 CVE-2014-4427 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X
App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility API.
network
low complexity
apple CWE-264
7.5
2014-10-18 CVE-2014-4426 Information Exposure vulnerability in Apple mac OS X
AFP File Server in Apple OS X before 10.10 allows remote attackers to discover the network addresses of all interfaces via an unspecified command to one interface.
network
apple CWE-200
4.3