Vulnerabilities > Apple > MAC OS X

DATE CVE VULNERABILITY TITLE RISK
2009-01-21 CVE-2009-0002 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QTVR movie file with crafted THKD atoms.
network
apple microsoft CWE-119
critical
9.3
2009-01-21 CVE-2009-0001 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apple Quicktime
Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted RTSP URL.
network
apple microsoft CWE-119
critical
9.3
2009-01-15 CVE-2009-0123 Information Exposure vulnerability in Apple Safari
Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for RSS feeds.
7.1
2008-12-17 CVE-2008-4237 Multiple Security vulnerability in RETIRED: Apple Mac OS X 2008-008
Managed Client in Apple Mac OS X before 10.5.6 sometimes misidentifies a system when installing per-host configuration settings, which allows context-dependent attackers to have an unspecified impact by leveraging unintended settings, as demonstrated by the screen saver lock setting.
network
low complexity
apple
critical
10.0
2008-12-17 CVE-2008-4236 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
Apple Type Services (ATS) in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to cause a denial of service (infinite loop) via a crafted embedded font in a PDF file.
network
apple CWE-399
7.1
2008-12-17 CVE-2008-4234 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X and mac OS X Server
Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers to execute arbitrary code via an executable file with the content type indicating no application association for the file, which does not trigger a "potentially unsafe" warning message.
network
apple CWE-264
critical
9.3
2008-12-17 CVE-2008-4224 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
UDF in Apple Mac OS X before 10.5.6 allows user-assisted attackers to cause a denial of service (system crash) via a malformed UDF volume in a crafted ISO file.
network
apple CWE-20
7.1
2008-12-17 CVE-2008-4222 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
natd in network_cmds in Apple Mac OS X before 10.5.6, when Internet Sharing is enabled, allows remote attackers to cause a denial of service (infinite loop) via a crafted TCP packet.
network
apple CWE-399
7.1
2008-12-17 CVE-2008-4221 Resource Management Errors vulnerability in Apple mac OS X and mac OS X Server
The strptime API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted date string, related to improper memory allocation.
network
low complexity
apple CWE-399
critical
10.0
2008-12-17 CVE-2008-4220 Numeric Errors vulnerability in Apple mac OS X and mac OS X Server
Integer overflow in the inet_net_pton API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
network
low complexity
apple CWE-189
critical
10.0