Vulnerabilities > Apple > MAC OS X > 10.6.6

DATE CVE VULNERABILITY TITLE RISK
2011-10-14 CVE-2011-0224 Code Injection vulnerability in Apple mac OS X and mac OS X Server
CoreMedia in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QuickTime movie file.
network
apple CWE-94
6.8
2011-10-14 CVE-2011-0185 USE of Externally-Controlled Format String vulnerability in Apple mac OS X and mac OS X Server
Format string vulnerability in the debug-logging feature in Application Firewall in Apple Mac OS X before 10.7.2 allows local users to gain privileges via a crafted name of an executable file.
local
apple CWE-134
4.4
2011-09-12 CVE-2011-3422 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
The Keychain implementation in Apple Mac OS X 10.6.8 and earlier does not properly handle an untrusted attribute of a Certification Authority certificate, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via an Extended Validation certificate, as demonstrated by https access with Safari.
network
apple CWE-20
4.3
2011-07-07 CVE-2011-2192 Credentials Management vulnerability in multiple products
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
4.3
2011-06-30 CVE-2009-5078 7PK - Security Features vulnerability in multiple products
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.
network
low complexity
gnu apple CWE-254
6.4
2011-06-24 CVE-2011-1132 Denial of Service vulnerability in Apple Mac OS X IPV6 Socket Options (CVE-2010-1132)
The IPv6 implementation in the kernel in Apple Mac OS X before 10.6.8 allows local users to cause a denial of service (NULL pointer dereference and reboot) via vectors involving socket options.
local
low complexity
apple
4.9
2011-06-24 CVE-2011-0211 Numeric Errors vulnerability in Apple mac OS X, mac OS X Server and Quicktime
Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
network
apple CWE-189
6.8
2011-06-24 CVE-2011-0210 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X, mac OS X Server and Quicktime
QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted sample tables in a movie file.
network
apple CWE-119
6.8
2011-06-24 CVE-2011-0209 Numeric Errors vulnerability in Apple mac OS X, mac OS X Server and Quicktime
Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RIFF WAV file.
network
apple CWE-189
6.8
2011-06-24 CVE-2011-0208 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
QuickLook in Apple Mac OS X 10.6 before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document.
network
apple CWE-119
6.8