Vulnerabilities > Apple > MAC OS X

DATE CVE VULNERABILITY TITLE RISK
2010-11-16 CVE-2010-1844 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
Unspecified vulnerability in Image Capture in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (memory consumption and system crash) via a crafted image.
network
apple CWE-20
7.1
2010-11-16 CVE-2010-1843 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
Networking in Apple Mac OS X 10.6.2 through 10.6.4 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted PIM packet.
network
low complexity
apple CWE-20
7.8
2010-11-15 CVE-2010-1842 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Buffer overflow in AppKit in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a bidirectional text string with ellipsis truncation.
network
apple CWE-119
critical
9.3
2010-11-15 CVE-2010-1841 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
Disk Images in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted UDIF image.
network
apple CWE-20
critical
9.3
2010-11-15 CVE-2010-1840 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
network
low complexity
apple CWE-119
7.5
2010-11-15 CVE-2010-1838 Improper Authentication vulnerability in Apple mac OS X and mac OS X Server
Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle errors associated with disabled mobile accounts, which allows remote attackers to bypass authentication by providing a valid account name.
local
apple CWE-287
4.4
2010-11-15 CVE-2010-1837 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
CoreText in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a PDF document.
network
apple CWE-119
6.8
2010-11-15 CVE-2010-1836 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Stack-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.
network
apple CWE-119
6.8
2010-11-15 CVE-2010-1834 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
CFNetwork in Apple Mac OS X 10.6.x before 10.6.5 does not properly validate the domains of cookies, which makes it easier for remote web servers to track users by setting a cookie that is associated with a partial IP address.
network
apple CWE-20
5.8
2010-11-15 CVE-2010-1833 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple mac OS X and mac OS X Server
Apple Type Services (ATS) in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted embedded font in a document.
network
apple CWE-119
6.8